216.73.216.233

State-Sponsored Remote Wipe Tactics Targeting Android Devices

· Published 10/11/2025 11:14 · Modified 10/11/2025 11:48

Export JSON

Essential information

Published
10/11/2025 11:14
Modified
10/11/2025 11:48
Tags
2025-11-10 android apt endrat find hub google account kakaotalk lilithrat quasarrat rat remcosrat remote wipe rftrat social engineering spear-phishing
Related entities
10 observables, 1 intrusion sets (apt), 15 techniques (mitre), 5 malware, 1 others

Description

A new remote data-wipe attack exploiting Google's feature has been identified as part of the KONNI campaign. The attackers impersonated psychological counselors and human rights activists, distributing malware disguised as stress-relief programs via messenger. They compromised Google accounts to track victims' locations and remotely wipe devices. The attack involved , prolonged reconnaissance, and abuse of legitimate management functions. Multiple variants were deployed, including , , and . The campaign utilized WordPress-based hosting and geographically distributed C2 servers to evade detection. This sophisticated attack demonstrates the evolving tactics of state-sponsored threat actors.

External references