“A Date with Phishing and Stealers: Cybercrime in the Age of Loneliness”
# Contents
- Introduction
- Baseline
- Cases
- CASE #1 # PHISHING
[ Web app ] Movie session + the theft of payment information; - CASE #2 # STEALER
[ Mobile app ] A date + the theft of messages from banks; - Backstory
- The first glance
- Tasker
- Telegram bot
- License validation
- Communication with C&C server
- Debugging detection
- SMS & phone calls
- RAT mode
- "Sleep" mode
Stealing of SMS messages, Stealing of contacts + Blackmail mode, SMS spam, Stealing local files; - Other notes
Mentions in X (Twitter), Indicators of compromise; - CASE #3 # RAT
[ Mobile app ] Streaming service + remote control of the device; - Backstory
- The first glance
- Obfuscation
- Autostart
- Debugging detection
- Communication with C&C server
- Logging
- Audio recording
- Location tracking
- Gesture control
- CraxsBrowser
- Other injections into WebView
- Other notes
Language, Classification, Indicators of compromise; - Other cases
- Phishing
Websites that steal payment information, Websites that steal credentials; - Exploitation
Archives with photos and malware; - Food for thought
# Introduction
Scammers and hacker groups proceed to exploit human vulnerabilities to target internet users. Every year, the number of victims rises rapidly, and the attacks become more sophisticated. The threats are particularly prevalent in services designed to deal with loneliness and reach a peak during holidays when people are most likely to feel lonely.
It's undeniable that the issue of loneliness is becoming more pressing and critical every year, to the point where it can be described as an epidemic. While online dating can provide a solution, new methods of attack are emerging as technology advances. Unfortunately, attackers will certainly take advantage of any technical opportunities and human vulnerabilities to achieve their goals.
It has become interesting for me to look at the technical aspects of the structure of elements used in attacks on users that have recently been discovered in online dating, dating bots, and applications. I would also like to remind you about the techniques that attackers use to gain trust and sympathy, as well as the principles of minimizing risks for users.
It's undeniable that the issue of loneliness is becoming more pressing and critical every year, to the point where it can be described as an epidemic. While online dating can provide a solution, new methods of attack are emerging as technology advances. Unfortunately, attackers will certainly take advantage of any technical opportunities and human vulnerabilities to achieve their goals.
It has become interesting for me to look at the technical aspects of the structure of elements used in attacks on users that have recently been discovered in online dating, dating bots, and applications. I would also like to remind you about the techniques that attackers use to gain trust and sympathy, as well as the principles of minimizing risks for users.
WARNING!
This article was created for informational purposes only and is intended for security analysis specialists who analyze the security of the customer's resources strictly on legal grounds and on the basis of an agreement concluded with the customer company. The author is not responsible for any harm caused by the use of the information provided.
The spread of malware and disruption of systems are prosecuted by law.
Sensitive information is deliberately hidden.
This article was created for informational purposes only and is intended for security analysis specialists who analyze the security of the customer's resources strictly on legal grounds and on the basis of an agreement concluded with the customer company. The author is not responsible for any harm caused by the use of the information provided.
The spread of malware and disruption of systems are prosecuted by law.
Sensitive information is deliberately hidden.
# Baseline
This section discusses the conditions under which the study was conducted. We discuss how we, as a society, got to this point and who & where is more likely to become a victim.
## Loneliness epidemic
In today's world, people are exposed to a wide range of different factors that directly affect the quality of their social interactions and, consequently, satisfaction of one of the most fundamental human needs. The increasing amount of time that sometimes just needs to be spent on a phone or a laptop, the lack of an urgent need to visit public places as a result of the development of various delivery services, a culture of proactive self–care that can easily cross the line and turn into glorification of egocentrism and rejection of society in favor of oneself, ... – all these are aspects of everyday reality that certainly leave a mark on every member of the generation.
Loneliness is a major topic of social research and, as a significant problem affecting the entire world, it also affects Russia. For example, here are some alarming excerpts from a scientific study done by the Higher School of Economics on Russian residents experiencing pressure from loneliness:
And here are the statistics on people living alone – those citizens who live independently, as part of a "household" consisting only of one person, according to the Federal State Statistics Service:

Some people find comfort in loneliness. Nevertheless, it cannot be denied that the dragging feeling of loneliness is the body's response to the dissatisfaction of a need and by definition cannot be pleasant. It is a gnawing feeling designed to push a person to a well–defined action – social interaction. With the advent of this feeling, any, even conscious, solitude ceases to be healthy. And everyone who has experienced loneliness knows that it is difficult to cope with it on your own.
The number of factors contributing to the problem of loneliness is increasing, and as a result, the number of online services designed to fight loneliness, ranging from online dating applications to content subscription services, and the number of people who resort to using such services has also grown:

Dating App Downloads Explode After Years of Stagnation
According to researches conducted by analytical centers, more than 2/3 of young people in Russia have registered on online dating websites and mobile applications, and 1/4 are currently using them.
Loneliness is a major topic of social research and, as a significant problem affecting the entire world, it also affects Russia. For example, here are some alarming excerpts from a scientific study done by the Higher School of Economics on Russian residents experiencing pressure from loneliness:
It turned out that over 43% of Russians experience loneliness in some way or another. <...> Youth is not a barrier to loneliness, either. Approximately one third of 14-29 year old Russians face this issue.
Source: HSE
Source: HSE
And here are the statistics on people living alone – those citizens who live independently, as part of a "household" consisting only of one person, according to the Federal State Statistics Service:

More than 40% of households in Russia are single-person households, and their proportion has doubled in the last 20 years, according to the census. <...> Among the reasons for the increase in the number of single-person households is late marriage. <...> The predominance of single-person households was recorded for the first time in the history of population censuses in the Russian Federation.
Source: RBK Daily
Source: RBK Daily
Some people find comfort in loneliness. Nevertheless, it cannot be denied that the dragging feeling of loneliness is the body's response to the dissatisfaction of a need and by definition cannot be pleasant. It is a gnawing feeling designed to push a person to a well–defined action – social interaction. With the advent of this feeling, any, even conscious, solitude ceases to be healthy. And everyone who has experienced loneliness knows that it is difficult to cope with it on your own.
The number of factors contributing to the problem of loneliness is increasing, and as a result, the number of online services designed to fight loneliness, ranging from online dating applications to content subscription services, and the number of people who resort to using such services has also grown:

According to researches conducted by analytical centers, more than 2/3 of young people in Russia have registered on online dating websites and mobile applications, and 1/4 are currently using them.
## My male identity
Despite the fact that researches on loneliness show a similar gender distribution in the results, men still prevail among users of dating services. For example, The Russian dating app called "Mamba" reported, that more than half of its audience are men. This is also reflected in the statistics of another popular dating app, Tinder:

Tinder gender ratios, as of May 2023
Compared to women, men are more likely to like a person instead of passing on them, and they are also less likely to receive mutual likes:

Despite being far more selective, women still match more frequently than men on Tinder
This is also why men are more likely to be victims of online dating scammers: posing as a beautiful girl, it is easier for the attacker to establish a communication channel, since the likelihood of being swiped left decreases, it is easier to win over and gain trust in order to carry out additional actions (make user interact with a website, install an application, execute a file with a malicious payload in it, ...).
To take a closer look at the situation, I created Nikita and registered him on various social media platforms, messengers and dating apps, added him to relevant groups and launched chatbots.

Compared to women, men are more likely to like a person instead of passing on them, and they are also less likely to receive mutual likes:

This is also why men are more likely to be victims of online dating scammers: posing as a beautiful girl, it is easier for the attacker to establish a communication channel, since the likelihood of being swiped left decreases, it is easier to win over and gain trust in order to carry out additional actions (make user interact with a website, install an application, execute a file with a malicious payload in it, ...).
To take a closer look at the situation, I created Nikita and registered him on various social media platforms, messengers and dating apps, added him to relevant groups and launched chatbots.


| Full name | Nikita Konstantinovich Sheremetyev |
|---|---|
| Gender | Men |
| Age | 24 years old |
| Date of birth | Jan 13, 2000 |
| City | Moscow |
| Phone number | +7 (* * *) * * * * (virtual) |
| E-mail address | * * * * @ * * * (temporary) |
| Nickname | @ * * * * * |
# Cases
During the week of pretending to be a non-existent young man, I often swiped to the right and liked other users of each of the mentioned services, but I intentionally did not initiate any conversations (*It turned out that Telegram limits one's ability to send messages first if they have a virtual number linked to their account: which means I missed out on several potential attackers and harmful links/files)
Despite the lack of initiative on his part, Nikita received messages from several women. Most of these messages turned out to be malicious. The material they distributed became the basis for my research project.
The situations described below demonstrates the current state of affairs regarding malware in online dating, and provides information on:
Despite the lack of initiative on his part, Nikita received messages from several women. Most of these messages turned out to be malicious. The material they distributed became the basis for my research project.
The situations described below demonstrates the current state of affairs regarding malware in online dating, and provides information on:
- Social engineering techniques
- Technical features of each sample
- Consequences for victims
- Information on detection of malicious activity
## Case #1
Movie session + the theft of payment information;
##~ Website interface
The first girl offered to meet and go to the theater, and even showed a website where tickets could be purchased. This is a common scenario for scammers who prey on people looking for dating, but despite its popularity, it continues to expand beyond the borders of Russia.
The website's domain name is short and catchy, except for the fact that the top-level domain = "
The website's domain name is short and catchy, except for the fact that the top-level domain = "
.online". The website pages look professional: with widgets for contacting support and requesting a callback, information sections and news. There is even a warning about fake lookalike websites:
The site provides a list of upcoming performances, where you can place an order for tickets. After previewing the partially filled hall plan, you can select the seats:

The first red flag: the order page. The executable script has a typo in the name (
ordening.php), unquestionably accepts the price from the amount request parameter and explicitly processes promo codes (CLUB15FREE and NEWYEAR15 are available):
##~ Payment interface
Payment process includes a redirection of the user to another domain, which has the substring "3-DS" in it, causing an association with 3-D Secure online payment technology. This time, the top-level domain is = "
This interface provides the user with a variety of payment options:
.ru".This interface provides the user with a variety of payment options:

The redirection to the next interface depends on the chosen payment method.
The second red flag: in the case of the Faster Payments System, users are asked to make payments themselves, using the phone number or card details provided on the webpage. These details are updated approximately once a day:
The second red flag: in the case of the Faster Payments System, users are asked to make payments themselves, using the phone number or card details provided on the webpage. These details are updated approximately once a day:

If the bank is selected, a form for entering a card is displayed in front of the user. On click of the payment button, the script verifies the filling out of the form and the prefix of the inputted card number. If the required conditions are met, it shows an animation of establishing a connection with the bank:

The third red flag: if you look at the output of the developer tools, you will see that the payment information entered by the user is sequentially sent to the server as a
bin request parameter as the keys are pressed. This looks like a harmless check of a bank identification number, but in this case the script is not limited to processing the BIN. The technique provides attackers with an additional way to extract the entered information. Even if the user becomes suspicious and changes their mind about clicking the payment button, their keystrokes will still be logged and sent to the server, and may be found in its logs:
##~ Tickets generation
The fourth red flag: iterating through the endpoints leads to the discovery of a list of paths that cannot be found in the links among the frontend. The main one among them is the
/generate path, which leads to the ticket generation interface. The attackers took care of their accomplices by developing a form that generates electronic receipts in one click, and provided instructions on how to use it and reap the full benefit:

In the end, the resource was blocked on the territory of the Russian Federation.
## Case #2
A date + the theft of messages from banks;
##~ Backstory
Me and the second girl met on a dating app. She was the first to express interest and the first to initiate contact through private messages. After some time, she suggested switching to Telegram and wrote me her nickname, saying that the messenger was much more more convenient for her.
Among other things, she ran a personal Telegram channel. On this channel, she promised to share her photos (provided that her subscribers invite their friends to join the channel) and posted APK files: a poetry application and a chat, where, as she assures, she spends a lot of time.
Among other things, she ran a personal Telegram channel. On this channel, she promised to share her photos (provided that her subscribers invite their friends to join the channel) and posted APK files: a poetry application and a chat, where, as she assures, she spends a lot of time.

The files "
Вот мои стихи.apk" ("Here are my poems.apk") и "Знакомства 18+.apk" ("Dating 18+.apk") are the same size. Upon closer examination, it turned out that the applications contain the same functionality, with a slight difference in appearance. Therefore, I will only analyze one of them in more detail.##~ The first glance
The
Знакомства 18+ app requires the following hardware capabilities:android.hardware.faketouchandroid.hardware.telephony
accessibility component. The app icon depicts a heart:
The requested rights in accordance with
Activities:
Services:
Receivers:
AndroidManifest.xml:android.permission.CALL_PHONE
android.permission.DISABLE_KEYGUARD
android.permission.DRAW_OVERLAYS
android.permission.EXPAND_STATUS_BAR
android.permission.FOREGROUND_SERVICE
android.permission.INTERNET
android.permission.QUERY_ALL_PACKAGES
android.permission.READ_CALL_LOG
android.permission.READ_CONTACTS
android.permission.READ_EXTERNAL_STORAGE
android.permission.READ_PHONE_STATE
android.permission.READ_SMS
android.permission.RECEIVE_BOOT_COMPLETED
android.permission.RECEIVE_SMS
android.permission.SCHEDULE_EXACT_ALARM
android.permission.SEND_SMS
android.permission.SYSTEM_ALERT_WINDOW
android.permission.VIBRATE
android.permission.WAKE_LOCK
android.permission.WRITE_CONTACTS
android.permission.WRITE_EXTERNAL_STORAGE
android.permission.WRITE_SMS
disabled_android.permission.READ_CALENDAR
disabled_android.permission.WRITE_CALENDAR
net.dinglisch.android.taskerm.Kid, net.dinglisch.android.taskerm.ProxyTransparent, net.dinglisch.android.taskerm.DummyActivity, net.dinglisch.android.taskerm.SceneActivity, net.dinglisch.android.taskerm.SceneActivityResize, com.joaomgcd.taskerm.genericaction.ActivityGenericAction, com.joaomgcd.taskerm.genericaction.ActivityGenericActionForResultnet.dinglisch.android.taskerm.ExecuteService, net.dinglisch.android.taskerm.MonitorService, net.dinglisch.android.taskerm.MyAccessibilityService, com.joaomgcd.taskerm.plugin.ServiceRequestQuery, com.joaomgcd.taskerm.plugin.ServicePluginFinished, com.joaomgcd.taskerm.genericaction.ActivityGenericAction, com.joaomgcd.taskerm.genericaction.ServiceGenericActionJobs –
–
net.dinglisch.android.taskerm ReceiverStaticAlwaysOn (net.dinglisch.android.taskerm.WILLYUM, net.dinglisch.android.taskerm.AWAKEY, android.intent.action.BOOT_COMPLETED, android.intent.action.PACKAGE_ADDED, android.intent.action.PACKAGE_REPLACES, android.intent.action.PACKAGE_REMOVED, android.intent.action.MY_PACKAGE_REPLACED);–
net.dinglisch.android.taskerm ReceiverStaticInternal (android.intent.action.DATE_CHANGED, android.intent.action.TIME_SET, android.intent.action.TIMEZONE_CHANGED, net.dinglisch.android.tasker.SMSEY);Also, the value of
android:versionName in the AndroidManifest.xml contains a curious structure that indicates the name of the team, the user's displayed name and nickname, and the Telegram chat ID: