Asin Android Spyware: Arabic-Language Fake News and War Map Apps Targeting Journalists

·

ESET researchers disclosed on June 5, 2026 a novel Android spyware family designated Asin, active since early 2025 across at least three distinct campaign waves. Each wave deployed purpose-built fake applications mimicking conflict-tracking utilities, PDF editors, and government news portals — all designed to appeal specifically to Arabic-speaking journalists, OSINT investigators, and conflict researchers tracking Middle Eastern events.

The lure strategy is precise: three of five known fake apps — GovLens, WarMap, and Syria Defense Map — are tools that a regional investigative journalist or OSINT practitioner would plausibly install. Infected APKs were distributed via purpose-registered domains that convincingly impersonate legitimate platforms, including a site mimicking the Live Universal Awareness Map (Liveuamap). Victims from Türkiye and Saudi Arabia have been confirmed in ESET telemetry.

This post provides a complete DFIR analysis: delivery infrastructure, spyware capabilities, known IOCs, Android forensic investigation steps, and detection logic for mobile security teams and IR practitioners.

◈ Table of Contents

01 Campaign Overview & Timeline 02 Delivery Infrastructure — 5 Fake Apps 03 Spyware Capabilities 04 Target Profile Analysis 05 DFIR — Android Forensic Investigation 06 Indicators of Compromise 07 Detection & Defensive Measures 08 MITRE ATT&CK Mapping 09 Sources
🕐

Phase 1 — Campaign Overview & Timeline

CONTEXT
01
Multi-Wave Campaign — Early 2025 to June 2026
Timeline

Asin was not a single-incident deployment. ESET identified at least three distinct waves, each using a different fake application and distribution domain. The consistent targeting of conflict-related and journalist-relevant tools across all waves points to a deliberate, operationally focused surveillance campaign rather than opportunistic malware distribution.

Confirmed Wave Timeline
  • 1Wave 1 — January 20, 2025: Domain live-war-map[.]com registered, distributing a fake war-map tracking application. The domain name directly mimics Liveuamap, a legitimate and well-known platform used by journalists and OSINT researchers to track global conflicts, human rights incidents, and geopolitical events. A Telegram channel associated with this wave further mimics the Liveuamap branding.
  • 2Wave 2 — May 27–29, 2025: Two new domains registered in rapid succession: govlens[.]net (registered May 27) impersonating a government news aggregation service, and pdf-reader[.]help (registered May 29) impersonating a secure PDF editor. Both deliver Asin-infected APKs that include functional app decoy components to avoid immediate detection.
  • 3Wave 3 — October–January 2025–2026: An Asin APK sample uploaded to VirusTotal from Türkiye in October 2025. A second sample distributed from domain c-pdf[.]net detected in December 2025 on a Xiaomi Redmi Note 13 Pro (Android 15). A third sample — Syria Defense Map — detected on a Xiaomi Redmi Note 13 Pro+ 5G (Android 15) in mid-January 2026.
  • 4June 5, 2026: ESET publishes public disclosure. Campaign attributed to an unidentified threat actor. Primary attribution unknown — ESET lists Asin among "noteworthy campaigns from lesser-known and unattributed clusters" in their Q4 2025–Q1 2026 APT Activity Report.
🌐

Phase 2 — Delivery Infrastructure

DELIVERY
01
Five Fake Applications Across Three Domains
Infrastructure

Each delivery domain hosts a convincing fake website distributing an APK. The actor invested in domain names and site design that would pass a casual legitimacy check from a target who already expects to find such an application. None of these applications were distributed via Google Play — all require sideloading.

DomainFake ApplicationImpersonatesRegistration Date
govlens[.]netGovLensGovernment news aggregatorMay 27, 2025
pdf-reader[.]helpSecurePDF / PDF ReaderSecure PDF editor utilityMay 29, 2025
live-war-map[.]comWarMap / LiveWarMapLiveuamap conflict trackerJanuary 20, 2025
c-pdf[.]netC-PDFSecure PDF editor variantNot confirmed
[Telegram channel]Syria Defense MapSyria-focused conflict intelligenceNot confirmed
Social Engineering Mechanics
  • 1Functional decoy apps: Each infected APK embeds a legitimate functional component — the app actually displays news, renders PDFs, or shows map data. This delays detection by ensuring the target does not immediately notice malicious behavior and uninstall.
  • 2Manual sideload required: Victims are directed to enable "Install from Unknown Sources" on their Android devices. The social engineering context — believing they are installing a specialized conflict-tracking or press tool — makes this less suspicious than it would otherwise be.
  • 3Permission escalation post-install: After installation, Asin requests the permissions it needs for full surveillance capabilities. The permission requests are presented in the context of the legitimate app functionality (e.g., location access "for the map feature," contacts access "for source management").
  • 4Telegram as secondary distribution: A Telegram channel associated with the WarMap campaign pushed links to the APK directly to potential targets. This channel mimicked the naming convention of the legitimate Liveuamap service's Telegram presence.

None of these domains or APKs appeared in Google Play. Sideloading was required in all confirmed infections. Organizations working with journalists, researchers, or regional analysts in Arabic-speaking areas should explicitly prohibit APK sideloading on work devices and implement MDM policies that enforce this restriction.

🔍

Phase 3 — Spyware Capabilities

CAPABILITIES
01
Full Surveillance Capability Profile
Malware Behavior

Asin is a fully featured surveillance-grade spyware, not a commodity infostealer. Its capability set maps to the needs of an operator collecting intelligence on a human target — contact networks, communications, location, and real-time audio/visual access — rather than financial credential theft.

CapabilityImplementationIntelligence Value
SMS & Call LogsREAD_SMS, READ_CALL_LOG permissions; accesses Android ContentProvider for bothSource identification, communication patterns, contact network mapping
Contacts ExfiltrationREAD_CONTACTS permission; dumps full contact database including notes and relationship fieldsMaps the target's professional and personal network — high-value for counterintelligence
Real-time LocationACCESS_FINE_LOCATION + ACCESS_BACKGROUND_LOCATION; continuous GPS tracking even when app is closedTarget movement patterns, meeting locations, border crossings, safe house identification
Microphone AccessRECORD_AUDIO permission; ambient recording capabilityIn-person conversations, interviews, source meetings — most sensitive capability for journalists
Camera AccessCAMERA permission; photo capture on demand or triggered by C2Document capture, meeting participants, environmental reconnaissance
File System AccessREAD_EXTERNAL_STORAGE; targets documents, downloads, and media directoriesDraft articles, leaked documents, source materials, secure messaging exports
Installed App InventoryQUERY_ALL_PACKAGES permission; enumerates all installed applicationsIdentifies secure communication apps (Signal, Wickr, Briar) for targeted interception focus
Clipboard MonitoringClipboardManager listener; captures copied textPasswords, API keys, sensitive text copied between applications

For journalists and human rights researchers, the most dangerous capability combination is microphone access plus contacts exfiltration. An operator who knows both who the target's sources are (contacts) and can listen to conversations (microphone) can identify confidential sources even without direct access to encrypted messaging content — the encryption is irrelevant if the physical meeting is being recorded.

🎯

Phase 4 — Target Profile Analysis

TARGETING
01
Why Journalists and OSINT Researchers?
Analysis

ESET's analysis of the lure selection strongly suggests the targeting is deliberate and operationally motivated rather than opportunistic. Three of five fake applications are tools that would only be sought by someone actively monitoring conflicts, tracking government activities, or investigating regional events.

📰

Investigative Journalists

Arabic-language journalists covering Middle East conflicts, government activities, or regional geopolitics. The GovLens and WarMap lures directly target this audience. Source confidentiality is the primary risk.

🗺️

OSINT Researchers

Open-source intelligence practitioners tracking conflicts via Liveuamap-style tools. The live-war-map[.]com lure explicitly mimics a platform this community uses daily. The Syria Defense Map variant is even more targeted.

🏛️

Civil Society & Activists

Human rights monitors, civil society organizations, and political activists tracking events in conflict zones. The government news source impersonation (govlens[.]net) targets those monitoring official communications.

Confirmed Victim Indicators (from ESET Telemetry)
  • 1Türkiye (October 2025): APK sample uploaded to VirusTotal from a Turkish IP address — consistent with either a Turkish user being targeted or a Turkish-based researcher analyzing the malware.
  • 2Saudi Arabia / Arabic-speaking region (December 2025 – January 2026): Devices confirmed infected include Xiaomi Redmi Note 13 Pro and Pro+ 5G running Android 15. The specific device models are consistent with usage patterns in the Middle East and North Africa region.
  • 3Unattributed threat actor: ESET has not publicly attributed this campaign to a known state-sponsored group or cybercrime operator. The targeting profile — journalists and OSINT researchers in Arabic-speaking regions — is consistent with state-level intelligence interests from multiple regional actors.
🔬

Phase 5 — DFIR: Android Forensic Investigation

INVESTIGATION
01
On-Device Triage — Identifying Asin Without Forensic Tools
Triage

When a target device is physically accessible, these checks can confirm or rule out Asin infection without specialist tools. For high-risk individuals (journalists, activists, researchers), any confirmed indicator warrants immediate device isolation and replacement.

Manual Triage Checklist
  • 1Check installed apps for Asin lures: Settings → Apps → See All. Look for any application named GovLens, WarMap, LiveWarMap, Syria Defense Map, C-PDF, or SecurePDF that was not installed from Google Play. If the app icon looks like a news, map, or PDF utility but is not from the official Play Store, treat it as suspicious.
  • 2Review app permissions: Settings → Apps → [Suspicious App] → Permissions. An app claiming to be a PDF editor requesting location, microphone, camera, and contacts access has no legitimate reason for those permissions. Any app with this combination is either Asin or comparable spyware.
  • 3Check battery and data usage: Settings → Battery → Battery Usage. Background processes running when the app is not open indicate surveillance activity. Settings → Mobile Data → App Data Usage. Unexpected background data from a "PDF editor" or "news app" is a strong indicator of active C2 communication.
  • 4Review Unknown Sources installs: Settings → Security → Install Unknown Apps. If any non-standard package installer is shown as having been granted this permission, it was used to sideload an APK. This permission should be disabled immediately after use and reviewed regularly.
  • 5Check for associated domains in DNS history: If the device uses a VPN or DNS logging is available, look for outbound connections to govlens[.]net, c-pdf[.]net, live-war-map[.]com, pdf-reader[.]help. Any DNS resolution of these domains confirms the app was downloaded or is actively beaconing.
02
ADB / MVT Forensic Extraction
Forensics

For devices belonging to at-risk individuals or those suspected of compromise in an organizational context, the Mobile Verification Toolkit (MVT) developed by Amnesty International provides the most thorough Android forensic capability. ADB commands provide a first-pass triage.

ADB — List installed packages and check for sideloaded APKs
# List all third-party (non-system, non-Play Store) installed packages $ adb shell pm list packages -3 -i # Check install source — legit Play Store apps show "com.android.vending" # Sideloaded APKs show "null" or "adb" as installer $ adb shell pm list packages -3 --show-versioncode | while read pkg; do name=$(echo $pkg | cut -d: -f2 | cut -d= -f1) installer=$(adb shell pm get-install-source $name 2>/dev/null) echo "$name → $installer" done # Check app permissions granted to suspicious packages $ adb shell dumpsys package [SUSPICIOUS_PACKAGE_NAME] | grep -E "RECORD_AUDIO|READ_SMS|ACCESS_FINE_LOCATION|CAMERA|READ_CONTACTS" # Pull APK for hash comparison against known Asin samples $ adb shell pm path [SUSPICIOUS_PACKAGE_NAME] adb pull [PATH_FROM_ABOVE] ./suspicious.apk sha256sum suspicious.apk
MVT — Full Android forensic acquisition
# Install Mobile Verification Toolkit (Amnesty International) $ pip install mvt # Download ESET IOCs (domains, hashes) as MVT-compatible format $ wget -O asin_iocs.stix2 [IOC feed URL from ESET when available] # Run MVT Android check over ADB (device must have USB debugging enabled) $ mvt-android check-adb --iocs asin_iocs.stix2 --output ./asin_investigation/ # Analyze backup (if ADB backup is available) $ adb backup -all -apk -shared -f device_backup.ab mvt-android check-backup --iocs asin_iocs.stix2 \ --output ./asin_investigation/ device_backup.ab
MVT Artifacts to Collect
  • SMS history — identifies C2 SMS commands (some Android spyware uses SMS for command delivery)
  • Call log — pattern analysis for unusual short calls indicating C2 check-in
  • Installed apps with permissions — full permission audit output
  • Network connections — outbound connections to Asin delivery domains
  • Browser history — visits to delivery domains (govlens[.]net etc.) indicating download source
  • Processes — running processes at time of acquisition
03
Incident Response — Compromised Journalist or Researcher
IR

If Asin infection is confirmed on a device belonging to a journalist, OSINT researcher, or civil society actor, the response priorities differ from a corporate security incident. Source protection and evidence preservation must be balanced against the personal safety of the device owner.

High-Risk Individual IR Protocol
  • 1Do NOT immediately notify sources: If the device has been infected and communications have been monitored, notifying sources via the compromised device may alert the threat actor that detection has occurred. Establish a clean out-of-band communication channel first.
  • 2Physical device isolation: Power off the device (do not factory reset immediately — preserve forensic evidence). Remove SIM card. Place in a Faraday bag if available to prevent any remote wipe commands from reaching the device while evidence is preserved.
  • 3Forensic acquisition before reset: If the individual consents and the organizational context requires it, perform MVT acquisition before resetting. This evidence may be needed for accountability, legal action, or to identify other targets in the same campaign.
  • 4Source notification (clean channel): After establishing a clean device, use Signal on a new number to notify any sources who may have been identified through the compromised device's contacts or communications. Assess whether their safety is at risk.
  • 5Replace, don't reset: Factory reset does not guarantee spyware removal on rooted or heavily modified Android devices. For high-risk individuals, device replacement is the recommended remediation. The compromised device should be preserved for forensics, not returned to use.
📋

Phase 6 — Indicators of Compromise

IOCs
TypeIndicatorNotes
Domaingovlens[.]netWave 2 delivery domain — fake government news app. Registered May 27, 2025.
Domainpdf-reader[.]helpWave 2 delivery domain — fake PDF editor. Registered May 29, 2025.
Domainlive-war-map[.]comWave 1 delivery domain — fake Liveuamap clone. Registered January 20, 2025.
Domainc-pdf[.]netWave 3 delivery domain — fake PDF variant. Registration date unconfirmed.
App NameGovLensFake government news application — Asin-infected APK from govlens[.]net
App NameWarMap / LiveWarMapFake conflict tracker — Asin-infected APK mimicking Liveuamap
App NameSyria Defense MapFake Syria conflict map — detected January 2026, distributed via Telegram
App NameC-PDF / SecurePDFFake PDF editor — Asin-infected APK from c-pdf[.]net
Device (victim)Xiaomi Redmi Note 13 Pro (Android 15)Confirmed infection — APK from c-pdf[.]net, December 2025
Device (victim)Xiaomi Redmi Note 13 Pro+ 5G (Android 15)Confirmed infection — Syria Defense Map, mid-January 2026
VT UploadAPK uploaded from Türkiye — October 2025First known public sample submission to VirusTotal
Permission SetREAD_SMS + READ_CALL_LOG + ACCESS_FINE_LOCATION + RECORD_AUDIO + CAMERA + READ_CONTACTS + READ_EXTERNAL_STORAGEFull Asin permission profile — this combination from a non-Google-Play app is high-confidence indicator
🛡️

Phase 7 — Detection & Defensive Measures

DEFENSE
01
MDM & Network Detection Rules
Detection
DNS Sinkhhole / Firewall Block — Asin Delivery Domains
# Add Asin delivery domains to DNS block list / firewall deny rules # These domains serve no legitimate purpose and should be blocked organization-wide BLOCK_LIST=( "govlens.net" "pdf-reader.help" "live-war-map.com" "c-pdf.net" ) # For Pi-hole / AdGuard Home for domain in "${BLOCK_LIST[@]}"; do echo "0.0.0.0 $domain" >> /etc/pihole/custom.list echo "0.0.0.0 www.$domain" >> /etc/pihole/custom.list done pihole restartdns # For enterprise DNS filtering (format for most NGFW/Umbrella/Zscaler) govlens.net → BLOCK (threat category: spyware delivery) pdf-reader.help → BLOCK live-war-map.com → BLOCK c-pdf.net → BLOCK
MDM Policy — Prevent Sideloading (Android Enterprise)
# Android Enterprise / Intune — block unknown source installs via MDM policy # Microsoft Intune: Device Configuration → Restrictions → Android Enterprise Allow installation from unknown sources: Block Google Play Protect: Enable and enforce Unknown apps install: Not allowed # For MobileIron / Ivanti AllowNonMarketApps: false RequireDeviceEncryption: true AllowUntrustedCerts: false
Sigma Rule — Asin Domain Detection in DNS/Proxy Logs
title: Asin Android Spyware — Delivery Domain Access id: b3f9e102-7d4a-4f88-aa21-5c9e6b2d3f71 status: stable description: Detects DNS queries or HTTP requests to known Asin spyware delivery domains logsource: category: dns detection: selection: dns_query|contains: - 'govlens.net' - 'pdf-reader.help' - 'live-war-map.com' - 'c-pdf.net' condition: selection falsepositives: - None expected — these are purpose-registered malicious domains level: high tags: - attack.t1476 - attack.t1444 - attack.mobile
02
Hardening Guidance for At-Risk Individuals
Hardening
📱

Device Discipline

Install applications exclusively from Google Play. Never sideload APKs regardless of how compelling the source appears. Conflict-tracking tools from legitimate providers (Liveuamap, ACLED) are available on Play Store.

🔒

Permission Minimization

Audit app permissions quarterly. No news, map, or PDF app legitimately requires both microphone and location access simultaneously. Deny background location to all apps except dedicated mapping tools you explicitly trust.

🌐

Domain Verification

Before downloading any security or research tool, verify the domain against the official vendor's website. Fake domains like live-war-map[.]com closely resemble legitimate services. Use WHOIS to check registration date — new domains (<6 months) distributing APKs are red flags.

🔐

Compartmentalization

For high-risk journalists and researchers: use a dedicated "field" device for sensitive communication. Keep this device off personal accounts. Use Signal + Tor. Never install additional apps. Separate devices for work and research browsing.

🎯

Phase 8 — MITRE ATT&CK Mobile Mapping

ATT&CK MOBILE
Technique IDTechnique NameAsin Implementation
T1476Deliver Malicious App via Other MeansAPK distributed via actor-controlled websites, not Google Play — requires manual sideloading
T1444Masquerade as Legitimate ApplicationFunctional decoy app embedded — GovLens, WarMap, Syria Defense Map all provide real functionality
T1430Location TrackingACCESS_FINE_LOCATION + ACCESS_BACKGROUND_LOCATION — continuous GPS tracking
T1412Capture SMS MessagesREAD_SMS permission — full SMS content and metadata exfiltration
T1433Access Call LogREAD_CALL_LOG permission — call patterns and contact frequency mapping
T1432Access Contact ListREAD_CONTACTS permission — full contact database with notes and relationships
T1429Capture AudioRECORD_AUDIO permission — ambient microphone access for meeting and conversation recording
T1512Capture CameraCAMERA permission — on-demand photo capture triggered by C2
T1533Data from Local SystemREAD_EXTERNAL_STORAGE — document and media file exfiltration
T1418Software DiscoveryQUERY_ALL_PACKAGES — enumerates installed apps to identify secure messaging tools
📰

Phase 9 — Sources & References

SOURCES
The Hacker News — Android Spyware Asin Targets Arabic Users via Fake News, PDF and War Map Apps ESET — APT Activity Report Q4 2025–Q1 2026 (Primary Research Source) Help Net Security — Oil shipments, drone makers, and a poisoned code library targeted in recent APT campaigns Amnesty International — Mobile Verification Toolkit (MVT) Documentation

Check your organization's devices against Asin IOCs

Use the CyberHawk IOC Scanner to verify Asin delivery domains are blocked across your network perimeter. For mobile threat programs and journalist device security assessments, visit cyberhawkthreatintel.com/threats.

◈ Stay Connected

Follow CyberHawk Threat Intel for threat intelligence, deployment guides and hands-on SOC tooling content.

🌐 Website ▶️ YouTube ▶️ YouTube (2) 𝕏 Twitter / X ♪ TikTok ✈️ Telegram
🔍 IOC Scanner 🛠️ Live Tools 📚 Courses 🚨 Threat Intel 📝 Blog 📋 SOPs

"They can't exploit you if you are the Exploit."