The Earth Empusa threat group is distributing new Android spyware, dubbed ActionSpy, through watering hole attacks to targets Turkic minority group. The spyware is being spread via several pages distributed in the wild via phishing emails disguised as a download page of an Android video application popular in Tibet. The malware was first spotted in April 2020, but experts believe the spyware has been active at least since 2017. Spyware leverages a sequence of iOS exploits since 2016, since April 2020.”]
Source: https://securityaffairs.co/wordpress/104758/malware/earth-empusa-actionspy-spyware.html