Hamas Malware Infects Israeli Defense Force Phones

Hamas Malware Featured

As malware becomes more targeted on key organizations, we’re seeing more sensitive groups be singled out for attacks. Recently, the Israeli Defense Force suffered a wave of attacks after Hamas used malware to infiltrate its system. How did the infection get in, and what does Hamas’s malware do?

How the Infection Spread

The infection was spread using a catfishing campaign. Members of Hamas made attractive female profiles on social media and used them to talk to Israeli soldiers. They’d claim to be immigrants to the region, which allowed them to use basic Hebrew without raising suspicion. They’d also only maintain communication via text to maintain their cover.

Hamas Malware Apps

Once the catfishers had someone’s full attention, they’d encourage the target to download an app. This app, they claimed, was similar to Snapchat, except that photos only persisted for a short time. This made it easier to share private photos without any worry about them leaking.

The apps were called Catch&See, ZatuApp, and GrixyApp, and were malware carriers for Hamas. As soon as a soldier downloaded one of these apps, the app would put up a fake error message saying the target’s phone wasn’t compatible with the app.

The app would then pretend to uninstall itself, but in reality, the app simply hid its icon from the list of apps. This app then worked to open a backdoor for Hamas through which they could gain access to their target’s phone.

What Did the Malware Do?

Once the target downloaded and ran one of the above apps, it executed a Mobile Remote Access Trojan (MRAT). This essentially means the hacker can peek into what the user is doing and even grab files for themselves.

Hamas Malware Infection

The app asked for permission to use the camera, calendar, phone location, SMS messages, contacts, and the browser’s history. The malware would then scan the phone for installed apps, the device’s details, and any info about the internal storage.

Fortunately, these attacks were discovered and shut down relatively quickly, but not before dozens of soldiers were infected.

What We Can Learn From this Attack

Obviously, this attack wasn’t for unsuspecting civilians. This was a targeted campaign that isolated a specific group of individuals for the Hamas hackers to work with. However, we can still learn proper cybersecurity from this attack.

The main lesson we can take from this is the app’s distribution method. Instead of risking going through the app stores and their security, the Hamas hackers set up websites that looked convincingly real. This teaches us that downloading an unknown app from outside the app store can be highly dangerous.

Also, this attack shows how catfishing works. Malicious agents set up a fake profile and use this to trick people into doing their bidding. It’s always a good idea to double- and triple-check the validity of the person before you do anything they suggest.

Stranger Danger

The recent attack on Israeli soldiers tells us a lot about cybersecurity practices. Trusting someone you’ve never heard or seen in the flesh is risky, and downloading apps that aren’t on the official app store has its dangers.

Have you or anyone you know suffered a catfishing attack? Let us know below.

Subscribe to our newsletter!

Our latest tutorials delivered straight to your inbox

Simon Batt Avatar

Read next

Suzanne Simard sealed paper birch and Douglas fir seedlings inside plastic bags, fed them carbon-14 and carbon-13 dioxide, and nine days later found carbon had crossed between species through fungal threads in the British Columbia soil beneath her boots
A species of jellyfish called Turritopsis dohrnii can revert its adult cells back to a juvenile polyp stage when injured or starving, effectively restarting its life cycle, and biologists have so far failed to identify any natural limit to how many times it can do this.
A Japanese man named Jiroemon Kimura, who lived to 116, was born in 1897 when Queen Victoria still ruled and died in 2013, meaning a single human life personally overlapped with the invention of the airplane, the atomic bomb, the internet, and Instagram
The Hollywood sign originally read HOLLYWOODLAND when it was built in 1923 as a real estate advertisement for a housing development, and it was only meant to stand for 18 months, but nobody ever got around to taking it down and the city eventually adopted it as a landmark
Almost all of the world’s internet traffic does not travel by satellite but through fibre-optic cables lying on the ocean floor, a hidden web of wires crossing the deepest parts of the sea to connect the continents.
People who flip their phone face down on every table aren’t being secretive. They figured out that staying interruptible meant handing their time to whoever rang first
Twitch vs. Facebook Gaming vs. YouTube Gaming: What’s the Best Live Game Streaming Platform?
Chrome Extensions Ownership Transfer is a Direct Threat to You: How to Stay Safe