ngCERT Advisory on SKYGOFREE exploit

Risk:                 Medium

Damage:           High

Platforms:        Android OS, Windows OS & MAC OSX Variant

Date:                 20 February, 2018


SKYGOFREE is a malicious exploit that is targeted at Android Mobile devices, although MAC OSX and windows OS variants of the exploit also exists. SKYGOFREE is an exploit with about 48 different remote control capabilities. it is capable of tapping into text messages (SMS), emails, camera, photo gallery, GPS, voice calls, surrounding conversations and all functionality of an infected device.

Description and Consequences

SKYGOFREE is an exploit developed by Dark Caracal, a Lebanese based hacking group believed to be linked to the Lebanese government and have been engaged in cyber theft of gigabytes of data in over 21 different countries. SKYGOFREE has been around since 2015 and is used for espionage on a global scale. A research report released by a cybersecurity firm Lookout and the Electronic Frontier Foundation (EFF) shows evidence on how the group is linked to the Lebanese government.

SKYGOFREE android malware variant referred to as Pallas is a Trojanized version of legitimate mobile apps and it has been found in WhatsApp, Signal, Primo, Threema, Plus Messanger, Psiphon VPN, Orbot TOR proxy, fake Flash Player updates and fake Google Play Push apps. Pallas primarily depends on permissions granted to it on installation to access sensitive data on infected devices, according to Lookout/EFF report.


  • Stakeholders are advised to ensure all devices are kept up-to-date with latest patches and updates as soon as they are available.
  • Stakeholders are also advised to ensure trusted antivirus software is installed on devices and also kept up-to-date.
  • Only trusted and verified apps should be installed on devices. Which means stakeholders should avoid installing apps not found on the Google Play store on android devices.
  • Never allow personal (BYOD) devices on corporate networks unless they have been scanned and found to be clean.
  • Personal devices used for work should be controlled under a mobile device management policy.
  • If device is found to be infected, power-off the system using the hardware power switch on the device and disconnect the device from any connected network, that is, if it is connected to a network and then report the incident to ngCERT via phone: 07044642378, email: or using the Report an Incident Form on the ngCERT website:


Security Alert

& Advisory

Read More image
We Love to

Hear From You

Send Your Enquiry Here image
Join Our Newsletter