Lookout researchers have identified over a thousand spyware apps related to a threat actor likely based in Iraq. These samples have been aggressively deployed since February 2017, with several making their way onto the Google Play Store. Google removed at least one of the apps after Lookout alerted the company. Researchers found many similarities to another malware family that was first reported on in mid 2016. It seems likely that the actors behind SonicSpy are using a similar automated-build process, however their desktop tooling has not been recovered at this point in time.”]
Source: https://blog.lookout.com/sonicspy-spyware-threat-technical-research

