Exposed: Russian Military Targeted by Sophisticated Android Spyware Masquerading as Alpine Quest App


# Russian Military Targeted by Sophisticated Android Spyware Campaign

Cybersecurity researchers have uncovered a malicious campaign specifically targeting Russian military personnel through fake versions of Alpine Quest mapping software. The attack distributes sophisticated Android spyware disguised as legitimate mapping tools commonly used in military operations.

“The attackers hide this trojan inside modified Alpine Quest mapping software and distribute it through Russian Android app catalogs,” according to Doctor Web’s analysis. The malware, identified as Android.Spy.1292.origin, has been embedded in older versions of the software and circulated as a supposedly free version of the premium Alpine Quest Pro application.

The distribution methods have evolved over time. Initially, the malware was shared via links in a fake Telegram channel pointing to Russian app catalogs. Later, the attackers began distributing the trojanized version directly as an APK file under the guise of an app update.

What makes this campaign particularly effective is its targeting of software known to be used by Russian military personnel in active operation zones. The malicious app perfectly mimics the legitimate version’s appearance and functionality, allowing it to remain undetected while harvesting sensitive data including:

– Mobile phone numbers and account information
– Contact lists
– Current date and precise geolocation
– Information about stored files
– App version details

The spyware reports the victim’s location to a Telegram bot whenever it changes and can download additional modules to expand its capabilities. These modules enable the theft of confidential files, particularly those shared via Telegram and WhatsApp.

“Android.Spy.1292.origin not only allows user locations to be monitored but also confidential files to be hijacked,” Doctor Web warned. “Its expandable functionality enables a wider spectrum of malicious tasks.”

In a parallel development, Kaspersky has reported that major Russian organizations across government, finance, and industrial sectors are being targeted by a sophisticated Windows backdoor disguised as an update for ViPNet secure networking software. This backdoor can steal files and deploy additional malicious components on infected systems.

Security experts recommend downloading Android apps only from trusted sources and avoiding “free” versions of premium software from questionable sources.

Share This Article