A sneaky Android spyware operation targeting people in Pakistan. Dubbed GhostChat and detected as Android/Spy.GhostChat.A, this malicious app masquerades as a free dating chat platform.
It lures victims with fake female profiles that seem locked behind exclusive passcodes. In reality, these codes are hardcoded into the app a clever social engineering trick to build trust and urgency.
Once installed, GhostChat hijacks the device, stealing contacts, files, and ongoing data like new photos and documents. Google Play Protect blocks known versions, but users must enable it.
The app surfaced on VirusTotal on September 11, 2025, from Pakistan. It mimics a legit Google Play app’s icon but packs espionage tools.
Victims sideloading it from unknown sources grant broad permissions, including access to storage and contacts.
A fake login screen demands hardcoded credentials (username: “chat,” password: “12345”). After “login,” 14 locked profiles appear, each tied to a Pakistani WhatsApp number (+92 prefix).
Victims enter another hardcoded code to “unlock” and chat redirecting straight to WhatsApp, likely controlled by attackers with local SIMs.
All the while, GhostChat spies silently. It grabs device ID, exports contacts as a .txt file, and uploads images, PDFs, Word docs, Excel sheets, PowerPoint files, and Open XML formats to a command-and-control (C&C) server.
It even sets observers for new images and scans documents every five minutes. ESET shared details with Google as an App Defense Alliance partner.
GhostChat Mechanics and Deception Layers
GhostChat’s flow preys on romance scams. Distribution is unclear, but exclusivity via codes likely hooks victims alongside the APK.
No server validation means everything’s bundled app, logins, unlocks, WhatsApp links. This creates a “VIP access” illusion, masking its true goal: persistent surveillance.
Technical breakdown shows ruthless efficiency. Post-permissions, background tasks exfiltrate data immediately.
Content observers snag fresh media; periodic jobs hunt files. C&C communication uses HTTP posts, outlined in decompiled code. The app stays hidden, running even pre-login.
ESET stresses manual installs heighten risks. Android users should stick to Play Store and keep Play Protect on.
Related Attacks Expose Broader Spy Network
According to welivesecurity, ESET linked GhostChat to a multi-stage campaign by the same actor. The C&C server hosted batch scripts downloading a DLL from hitpak[.]org/notepad2.dll. These used “ClickFix” a trick fooling users into running malware via fake instructions.
Another tactic: GhostPairing. The same domain posed as Pakistan’s Ministry of Defence, luring QR code scans to link victims’ WhatsApp to attackers’ devices. This grants full chat access, echoing past ops like China-linked BadBazaar on Signal.
No firm attribution yet, but Pakistani focus and authority impersonation suggest local espionage ties. Full IoCs and samples live on ESET’s GitHub.
| Indicator Type | Value |
|---|---|
| Package Name | com.datingbatch.chatapp |
| C&C Domain | hitpak[.]org |
| Fake Sites | buildthenations[.]info, foxy580.github[.]io |
| DLL Payload | file.dll, notepad2.dll |
| Hardcoded Login | chat / 12345 |
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.
