Phone : +91 95 8290 7788 | Email : sales@itmonteur.net

Register & Request Quote | Submit Support Ticket

Home » Cyber Security News » Vulnerabilities & Exploits » TRU identifies mobile spyware campaign using fake Red Alert app in Israel

TRU identifies mobile spyware campaign using fake Red Alert app in Israel

TRU identifies mobile spyware campaign using fake Red Alert app in Israel

https://etimg.etb2bimg.com/thumb/msid-129603786,imgsize-5482,width-1200,height=627,overlay-etciso,resizemode-75/data-breaches/tru-identifies-mobile-spyware-campaign-using-fake-red-alert-app-in-israel.jpg


A targeted smishing campaign has been identified in which Israeli users received SMS messages impersonating official Home Front Command alerts and distributing a trojanized version of Israel’s Red Alert rocket warning Android app.

The malicious app preserves the legitimate rocket alert functionality, making it harder for users to detect, while also collecting sensitive data in the background. This includes SMS messages, contacts, location data, device accounts and information on installed apps.

The campaign was discovered on March 1, 2026, after Israeli citizens reported spoofed “Oref Alert” SMS messages containing shortened links and claims of app malfunction.

The APK uses a dual-stage loader that extracts and runs a legitimate version of the app as cover while requesting dangerous permissions. Once granted, it can access SMS databases, extract contacts with phone numbers and emails, track GPS location with geofencing logic, collect account information, and enumerate installed apps for exfiltration to a command-and-control server.

The malware also uses multiple evasion techniques, including spoofing signatures to resemble Google Play installs, overriding Android runtime fields for persistence, and triggering certain behaviors based on location. Obfuscation and dynamic method invocation make detection more difficult.

The campaign raises the risk of theft of OTPs, credentials and user profiles, particularly during periods of conflict-related tension.

  • Published On Mar 18, 2026 at 08:51 AM IST

Join the community of 2M+ industry professionals.

Subscribe to Newsletter to get latest insights & analysis in your inbox.

All about ETCISO industry right on your smartphone!




Information Security - InfoSec - Cyber Security - Firewall Providers Company in India

 

 

 

 

 

 

 

 

 

 

 

 

What is Firewall? A Firewall is a network security device that monitors and filters incoming and outgoing network traffic based on an organization's previously established security policies. At its most basic, a firewall is essentially the barrier that sits between a private internal network and the public Internet.

 

Secure your network at the gateway against threats such as intrusions, Viruses, Spyware, Worms, Trojans, Adware, Keyloggers, Malicious Mobile Code (MMC), and other dangerous applications for total protection in a convenient, affordable subscription-based service. Modern threats like web-based malware attacks, targeted attacks, application-layer attacks, and more have had a significantly negative effect on the threat landscape. In fact, more than 80% of all new malware and intrusion attempts are exploiting weaknesses in applications, as opposed to weaknesses in networking components and services. Stateful firewalls with simple packet filtering capabilities were efficient blocking unwanted applications as most applications met the port-protocol expectations. Administrators could promptly prevent an unsafe application from being accessed by users by blocking the associated ports and protocols.

 

Firewall Firm is an IT Monteur Firewall Company provides Managed Firewall Support, Firewall providers , Firewall Security Service Provider, Network Security Services, Firewall Solutions India , New Delhi - India's capital territory , Mumbai - Bombay , Kolkata - Calcutta , Chennai - Madras , Bangaluru - Bangalore , Bhubaneswar, Ahmedabad, Hyderabad, Pune, Surat, Jaipur, Firewall Service Providers in India

Sales Number : +91 95 8290 7788 | Support Number : +91 94 8585 7788
Sales Email : sales@itmonteur.net | Support Email : support@itmonteur.net

Register & Request Quote | Submit Support Ticket