s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-apk.ghost_chat

📛 Threat Title

Malware family: GhostChat

Category: GhostChat First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `apk.ghost_chat`. Printable name: GhostChat.

Indicators of Compromise (0)

No indicators of compromise on this threat.

References (1)

Remediations (10)

  • web:cyberpress.org

    A sophisticated Android spyware campaign targeting individuals through a deceptive mobile application dubbed " GhostChat ." This malware , detected as Android/Spy. GhostChat .A, disguises itself as a legitimate dating and chat platform to facilitate cyberespionage. The operators employ a combination of romance scam tactics and social engineering to infect devices, exfiltrate sensitive data, and ...

  • web:cybersecuritynews.com

    While victims engage with what they believe are real dating profiles, the spyware operates silently in the background, exfiltrating device data to a command-and-control server. The malware immediately collects device identifiers, contact lists, and files stored on the device including images, PDFs, and Microsoft Office documents. GhostChat establishes continuous surveillance by setting up ...

  • web:gbhackers.com

    The malicious app, named GhostChat and detected as Android/Spy. GhostChat .A, disguises itself as a dating chat platform but is actually built for data theft and surveillance.

  • web:grokipedia.com

    GhostChat is an Android spyware that targets individuals in Pakistan through romance scams, deceiving victims into installing a malicious application disguised as a dating or chat platform. The malware , publicly analyzed by ESET researchers in January 2026, is sideloaded from unofficial sources outside the Google Play Store.

  • web:malwaretips.com

    A sneaky Android spyware called GhostChat , which tricks Pakistan-based users with romance scams via WhatsApp. The malware grabs sensitive data like contacts, photos, and files from victims' devices. Threat actors pose as dating apps to hook targets. GhostChat mimics a legit chat platform named...

  • web:www.eset.com

    For a more detailed analysis of GhostChat , check out the latest ESET Research blog post, " Love? Actually: Fake dating app used as lure in targeted spyware campaign in Pakistan " on WeLiveSecurity.com. Make sure to follow ESET Research on T witter (today known as X), BlueSky, and Mastodon for the latest news from ESET Research..

  • web:www.helpnetsecurity.com

    Android romance spyware uses fake dating apps and WhatsApp chats to spy on victims, steal data, and monitor activity on infected devices.

  • web:www.pcrisk.com

    What are the biggest issues that malware can cause? Malware can secretly steal banking details and login credentials, encrypt or lock files, use a device to mine cryptocurrency, install additional malicious software, give attackers remote control, and carry out other harmful activities. What is the purpose of GhostChat malware ?

  • web:www.zscaler.com

    Key Takeaways ThreatLabz observed targeted malware intrusions that employed social engineering tactics, leveraging the Dalai Lama's 90th birthday through strategic web compromises to lure Tibetan community members and redirect them to attacker-controlled sites. Operation GhostChat and Operation PhantomPrayers, respectively, relied on multi-stage infection chains to deploy Ghost RAT and ...

  • web:zimperium.com

    A new Android malware family , GhostChat , is actively targeting messaging app users by distributing malicious APKs that mimic popular chat tools, including WhatsApp. Once installed, the malware injects malicious code into the app process to intercept messages, harvest credentials, and exfiltrate contact lists and media.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.