ESET researchers disclosed on June 5, 2026 a novel Android spyware family designated Asin, active since early 2025 across at least three distinct campaign waves. Each wave deployed purpose-built fake applications mimicking conflict-tracking utilities, PDF editors, and government news portals — all designed to appeal specifically to Arabic-speaking journalists, OSINT investigators, and conflict researchers tracking Middle Eastern events.
The lure strategy is precise: three of five known fake apps — GovLens, WarMap, and Syria Defense Map — are tools that a regional investigative journalist or OSINT practitioner would plausibly install. Infected APKs were distributed via purpose-registered domains that convincingly impersonate legitimate platforms, including a site mimicking the Live Universal Awareness Map (Liveuamap). Victims from Türkiye and Saudi Arabia have been confirmed in ESET telemetry.
This post provides a complete DFIR analysis: delivery infrastructure, spyware capabilities, known IOCs, Android forensic investigation steps, and detection logic for mobile security teams and IR practitioners.
◈ Table of Contents
Phase 1 — Campaign Overview & Timeline
CONTEXTAsin was not a single-incident deployment. ESET identified at least three distinct waves, each using a different fake application and distribution domain. The consistent targeting of conflict-related and journalist-relevant tools across all waves points to a deliberate, operationally focused surveillance campaign rather than opportunistic malware distribution.
- 1Wave 1 — January 20, 2025: Domain
live-war-map[.]comregistered, distributing a fake war-map tracking application. The domain name directly mimics Liveuamap, a legitimate and well-known platform used by journalists and OSINT researchers to track global conflicts, human rights incidents, and geopolitical events. A Telegram channel associated with this wave further mimics the Liveuamap branding. - 2Wave 2 — May 27–29, 2025: Two new domains registered in rapid succession:
govlens[.]net(registered May 27) impersonating a government news aggregation service, andpdf-reader[.]help(registered May 29) impersonating a secure PDF editor. Both deliver Asin-infected APKs that include functional app decoy components to avoid immediate detection. - 3Wave 3 — October–January 2025–2026: An Asin APK sample uploaded to VirusTotal from Türkiye in October 2025. A second sample distributed from domain
c-pdf[.]netdetected in December 2025 on a Xiaomi Redmi Note 13 Pro (Android 15). A third sample — Syria Defense Map — detected on a Xiaomi Redmi Note 13 Pro+ 5G (Android 15) in mid-January 2026. - 4June 5, 2026: ESET publishes public disclosure. Campaign attributed to an unidentified threat actor. Primary attribution unknown — ESET lists Asin among "noteworthy campaigns from lesser-known and unattributed clusters" in their Q4 2025–Q1 2026 APT Activity Report.
Phase 2 — Delivery Infrastructure
DELIVERYEach delivery domain hosts a convincing fake website distributing an APK. The actor invested in domain names and site design that would pass a casual legitimacy check from a target who already expects to find such an application. None of these applications were distributed via Google Play — all require sideloading.
| Domain | Fake Application | Impersonates | Registration Date |
|---|---|---|---|
| govlens[.]net | GovLens | Government news aggregator | May 27, 2025 |
| pdf-reader[.]help | SecurePDF / PDF Reader | Secure PDF editor utility | May 29, 2025 |
| live-war-map[.]com | WarMap / LiveWarMap | Liveuamap conflict tracker | January 20, 2025 |
| c-pdf[.]net | C-PDF | Secure PDF editor variant | Not confirmed |
| [Telegram channel] | Syria Defense Map | Syria-focused conflict intelligence | Not confirmed |
- 1Functional decoy apps: Each infected APK embeds a legitimate functional component — the app actually displays news, renders PDFs, or shows map data. This delays detection by ensuring the target does not immediately notice malicious behavior and uninstall.
- 2Manual sideload required: Victims are directed to enable "Install from Unknown Sources" on their Android devices. The social engineering context — believing they are installing a specialized conflict-tracking or press tool — makes this less suspicious than it would otherwise be.
- 3Permission escalation post-install: After installation, Asin requests the permissions it needs for full surveillance capabilities. The permission requests are presented in the context of the legitimate app functionality (e.g., location access "for the map feature," contacts access "for source management").
- 4Telegram as secondary distribution: A Telegram channel associated with the WarMap campaign pushed links to the APK directly to potential targets. This channel mimicked the naming convention of the legitimate Liveuamap service's Telegram presence.
None of these domains or APKs appeared in Google Play. Sideloading was required in all confirmed infections. Organizations working with journalists, researchers, or regional analysts in Arabic-speaking areas should explicitly prohibit APK sideloading on work devices and implement MDM policies that enforce this restriction.
Phase 3 — Spyware Capabilities
CAPABILITIESAsin is a fully featured surveillance-grade spyware, not a commodity infostealer. Its capability set maps to the needs of an operator collecting intelligence on a human target — contact networks, communications, location, and real-time audio/visual access — rather than financial credential theft.
| Capability | Implementation | Intelligence Value |
|---|---|---|
| SMS & Call Logs | READ_SMS, READ_CALL_LOG permissions; accesses Android ContentProvider for both | Source identification, communication patterns, contact network mapping |
| Contacts Exfiltration | READ_CONTACTS permission; dumps full contact database including notes and relationship fields | Maps the target's professional and personal network — high-value for counterintelligence |
| Real-time Location | ACCESS_FINE_LOCATION + ACCESS_BACKGROUND_LOCATION; continuous GPS tracking even when app is closed | Target movement patterns, meeting locations, border crossings, safe house identification |
| Microphone Access | RECORD_AUDIO permission; ambient recording capability | In-person conversations, interviews, source meetings — most sensitive capability for journalists |
| Camera Access | CAMERA permission; photo capture on demand or triggered by C2 | Document capture, meeting participants, environmental reconnaissance |
| File System Access | READ_EXTERNAL_STORAGE; targets documents, downloads, and media directories | Draft articles, leaked documents, source materials, secure messaging exports |
| Installed App Inventory | QUERY_ALL_PACKAGES permission; enumerates all installed applications | Identifies secure communication apps (Signal, Wickr, Briar) for targeted interception focus |
| Clipboard Monitoring | ClipboardManager listener; captures copied text | Passwords, API keys, sensitive text copied between applications |
For journalists and human rights researchers, the most dangerous capability combination is microphone access plus contacts exfiltration. An operator who knows both who the target's sources are (contacts) and can listen to conversations (microphone) can identify confidential sources even without direct access to encrypted messaging content — the encryption is irrelevant if the physical meeting is being recorded.
Phase 4 — Target Profile Analysis
TARGETINGESET's analysis of the lure selection strongly suggests the targeting is deliberate and operationally motivated rather than opportunistic. Three of five fake applications are tools that would only be sought by someone actively monitoring conflicts, tracking government activities, or investigating regional events.
Investigative Journalists
Arabic-language journalists covering Middle East conflicts, government activities, or regional geopolitics. The GovLens and WarMap lures directly target this audience. Source confidentiality is the primary risk.
OSINT Researchers
Open-source intelligence practitioners tracking conflicts via Liveuamap-style tools. The live-war-map[.]com lure explicitly mimics a platform this community uses daily. The Syria Defense Map variant is even more targeted.
Civil Society & Activists
Human rights monitors, civil society organizations, and political activists tracking events in conflict zones. The government news source impersonation (govlens[.]net) targets those monitoring official communications.
- 1Türkiye (October 2025): APK sample uploaded to VirusTotal from a Turkish IP address — consistent with either a Turkish user being targeted or a Turkish-based researcher analyzing the malware.
- 2Saudi Arabia / Arabic-speaking region (December 2025 – January 2026): Devices confirmed infected include Xiaomi Redmi Note 13 Pro and Pro+ 5G running Android 15. The specific device models are consistent with usage patterns in the Middle East and North Africa region.
- 3Unattributed threat actor: ESET has not publicly attributed this campaign to a known state-sponsored group or cybercrime operator. The targeting profile — journalists and OSINT researchers in Arabic-speaking regions — is consistent with state-level intelligence interests from multiple regional actors.
Phase 5 — DFIR: Android Forensic Investigation
INVESTIGATIONWhen a target device is physically accessible, these checks can confirm or rule out Asin infection without specialist tools. For high-risk individuals (journalists, activists, researchers), any confirmed indicator warrants immediate device isolation and replacement.
- 1Check installed apps for Asin lures: Settings → Apps → See All. Look for any application named GovLens, WarMap, LiveWarMap, Syria Defense Map, C-PDF, or SecurePDF that was not installed from Google Play. If the app icon looks like a news, map, or PDF utility but is not from the official Play Store, treat it as suspicious.
- 2Review app permissions: Settings → Apps → [Suspicious App] → Permissions. An app claiming to be a PDF editor requesting location, microphone, camera, and contacts access has no legitimate reason for those permissions. Any app with this combination is either Asin or comparable spyware.
- 3Check battery and data usage: Settings → Battery → Battery Usage. Background processes running when the app is not open indicate surveillance activity. Settings → Mobile Data → App Data Usage. Unexpected background data from a "PDF editor" or "news app" is a strong indicator of active C2 communication.
- 4Review Unknown Sources installs: Settings → Security → Install Unknown Apps. If any non-standard package installer is shown as having been granted this permission, it was used to sideload an APK. This permission should be disabled immediately after use and reviewed regularly.
- 5Check for associated domains in DNS history: If the device uses a VPN or DNS logging is available, look for outbound connections to
govlens[.]net,c-pdf[.]net,live-war-map[.]com,pdf-reader[.]help. Any DNS resolution of these domains confirms the app was downloaded or is actively beaconing.
For devices belonging to at-risk individuals or those suspected of compromise in an organizational context, the Mobile Verification Toolkit (MVT) developed by Amnesty International provides the most thorough Android forensic capability. ADB commands provide a first-pass triage.
- SMS history — identifies C2 SMS commands (some Android spyware uses SMS for command delivery)
- Call log — pattern analysis for unusual short calls indicating C2 check-in
- Installed apps with permissions — full permission audit output
- Network connections — outbound connections to Asin delivery domains
- Browser history — visits to delivery domains (govlens[.]net etc.) indicating download source
- Processes — running processes at time of acquisition
If Asin infection is confirmed on a device belonging to a journalist, OSINT researcher, or civil society actor, the response priorities differ from a corporate security incident. Source protection and evidence preservation must be balanced against the personal safety of the device owner.
- 1Do NOT immediately notify sources: If the device has been infected and communications have been monitored, notifying sources via the compromised device may alert the threat actor that detection has occurred. Establish a clean out-of-band communication channel first.
- 2Physical device isolation: Power off the device (do not factory reset immediately — preserve forensic evidence). Remove SIM card. Place in a Faraday bag if available to prevent any remote wipe commands from reaching the device while evidence is preserved.
- 3Forensic acquisition before reset: If the individual consents and the organizational context requires it, perform MVT acquisition before resetting. This evidence may be needed for accountability, legal action, or to identify other targets in the same campaign.
- 4Source notification (clean channel): After establishing a clean device, use Signal on a new number to notify any sources who may have been identified through the compromised device's contacts or communications. Assess whether their safety is at risk.
- 5Replace, don't reset: Factory reset does not guarantee spyware removal on rooted or heavily modified Android devices. For high-risk individuals, device replacement is the recommended remediation. The compromised device should be preserved for forensics, not returned to use.
Phase 6 — Indicators of Compromise
IOCs| Type | Indicator | Notes |
|---|---|---|
| Domain | govlens[.]net | Wave 2 delivery domain — fake government news app. Registered May 27, 2025. |
| Domain | pdf-reader[.]help | Wave 2 delivery domain — fake PDF editor. Registered May 29, 2025. |
| Domain | live-war-map[.]com | Wave 1 delivery domain — fake Liveuamap clone. Registered January 20, 2025. |
| Domain | c-pdf[.]net | Wave 3 delivery domain — fake PDF variant. Registration date unconfirmed. |
| App Name | GovLens | Fake government news application — Asin-infected APK from govlens[.]net |
| App Name | WarMap / LiveWarMap | Fake conflict tracker — Asin-infected APK mimicking Liveuamap |
| App Name | Syria Defense Map | Fake Syria conflict map — detected January 2026, distributed via Telegram |
| App Name | C-PDF / SecurePDF | Fake PDF editor — Asin-infected APK from c-pdf[.]net |
| Device (victim) | Xiaomi Redmi Note 13 Pro (Android 15) | Confirmed infection — APK from c-pdf[.]net, December 2025 |
| Device (victim) | Xiaomi Redmi Note 13 Pro+ 5G (Android 15) | Confirmed infection — Syria Defense Map, mid-January 2026 |
| VT Upload | APK uploaded from Türkiye — October 2025 | First known public sample submission to VirusTotal |
| Permission Set | READ_SMS + READ_CALL_LOG + ACCESS_FINE_LOCATION + RECORD_AUDIO + CAMERA + READ_CONTACTS + READ_EXTERNAL_STORAGE | Full Asin permission profile — this combination from a non-Google-Play app is high-confidence indicator |
Phase 7 — Detection & Defensive Measures
DEFENSEDevice Discipline
Install applications exclusively from Google Play. Never sideload APKs regardless of how compelling the source appears. Conflict-tracking tools from legitimate providers (Liveuamap, ACLED) are available on Play Store.
Permission Minimization
Audit app permissions quarterly. No news, map, or PDF app legitimately requires both microphone and location access simultaneously. Deny background location to all apps except dedicated mapping tools you explicitly trust.
Domain Verification
Before downloading any security or research tool, verify the domain against the official vendor's website. Fake domains like live-war-map[.]com closely resemble legitimate services. Use WHOIS to check registration date — new domains (<6 months) distributing APKs are red flags.
Compartmentalization
For high-risk journalists and researchers: use a dedicated "field" device for sensitive communication. Keep this device off personal accounts. Use Signal + Tor. Never install additional apps. Separate devices for work and research browsing.
Phase 8 — MITRE ATT&CK Mobile Mapping
ATT&CK MOBILE| Technique ID | Technique Name | Asin Implementation |
|---|---|---|
| T1476 | Deliver Malicious App via Other Means | APK distributed via actor-controlled websites, not Google Play — requires manual sideloading |
| T1444 | Masquerade as Legitimate Application | Functional decoy app embedded — GovLens, WarMap, Syria Defense Map all provide real functionality |
| T1430 | Location Tracking | ACCESS_FINE_LOCATION + ACCESS_BACKGROUND_LOCATION — continuous GPS tracking |
| T1412 | Capture SMS Messages | READ_SMS permission — full SMS content and metadata exfiltration |
| T1433 | Access Call Log | READ_CALL_LOG permission — call patterns and contact frequency mapping |
| T1432 | Access Contact List | READ_CONTACTS permission — full contact database with notes and relationships |
| T1429 | Capture Audio | RECORD_AUDIO permission — ambient microphone access for meeting and conversation recording |
| T1512 | Capture Camera | CAMERA permission — on-demand photo capture triggered by C2 |
| T1533 | Data from Local System | READ_EXTERNAL_STORAGE — document and media file exfiltration |
| T1418 | Software Discovery | QUERY_ALL_PACKAGES — enumerates installed apps to identify secure messaging tools |
Phase 9 — Sources & References
SOURCESCheck your organization's devices against Asin IOCs
Use the CyberHawk IOC Scanner to verify Asin delivery domains are blocked across your network perimeter. For mobile threat programs and journalist device security assessments, visit cyberhawkthreatintel.com/threats.
◈ Stay Connected
Follow CyberHawk Threat Intel for threat intelligence, deployment guides and hands-on SOC tooling content.
"They can't exploit you if you are the Exploit."