Taiwanese Users Targeted by Stealthy PJobRAT Malware Disguised as Legitimate Chat Apps


# Android Malware “PJobRAT” Shifts Focus to Taiwan Users Through Fake Chat Apps

A sophisticated Android malware family known as PJobRAT, previously targeting Indian military personnel, has pivoted to Taiwan in a new campaign disguised as legitimate chat applications. The operation, which ran from January 2023 to October 2024, demonstrates how threat actors continuously adapt their tactics for different targets.

## Capabilities and Evolution

PJobRAT can steal sensitive information from infected Android devices, including:
– SMS messages
– Phone contacts
– Device and app information
– Documents and media files
– Location data
– Screen content (via accessibility services)

The latest variant introduces shell command execution capabilities, giving attackers enhanced control over compromised devices and potentially enabling WhatsApp chat theft.

## Attack Vector

The malware was distributed through fake chat applications named “SangaalLite” and “CChat,” downloadable from multiple WordPress sites. These apps featured basic chat functionality to appear legitimate while requesting extensive permissions that enabled background data collection.

The malicious apps used package names including:
– org.complexy.hard
– com.happyho.app
– sa.aangal.lite
– net.over.simple

## Technical Infrastructure

The updated PJobRAT employs a dual command-and-control approach:
– HTTP connections for uploading stolen data
– Firebase Cloud Messaging for sending shell commands and exfiltrating information

## Historical Context

First documented in 2021 but active since at least 2019, PJobRAT has been linked to a Pakistan-aligned threat actor called SideCopy (a possible sub-group of Transparent Tribe). Meta previously reported the group created fake romantic personas to trick targets into downloading malicious applications.

While this specific campaign appears to have ended, security researchers warn that the threat actors will likely retool and return with improved malware and adjusted tactics.

Share This Article