{"id":4641,"date":"2024-08-05T15:28:56","date_gmt":"2024-08-05T20:28:56","guid":{"rendered":"https:\/\/www.darkreading.com\/mobile-security\/sophisticated-android-spyware-targets-users-in-russia"},"modified":"2024-08-05T15:28:56","modified_gmt":"2024-08-05T20:28:56","slug":"sophisticated-android-spyware-targets-users-in-russia","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/08\/05\/sophisticated-android-spyware-targets-users-in-russia\/","title":{"rendered":"Sophisticated Android Spyware Targets Users in Russia"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt4249454de80f438f\/66b128b3d67a132a0697fec5\/spyware_Tero_Vesalainen_shutterstock.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/sophisticated-android-spyware-targets-users-in-russia.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/sophisticated-android-spyware-targets-users-in-russia.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">An unknown \u2014 and likely state-sponsored \u2014 threat actor has been using a previously unseen mobile spyware tool to spy on an unknown number of Android smartphone users. This activity has been ongoing for at least three years, according to researchers.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Until now, the campaign has focused mainly on targeted individuals in Russia, according to researchers at Kaspersky, who are tracking the threat as LianSpy. But the tactics that the spyware operators used in deploying the malware could be easily applied in other regions as well, Kaspersky says.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Post-Exploit Malware\">Post-Exploit Malware<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;LianSpy is a post-exploitation Trojan, meaning that the attackers either exploited vulnerabilities to root Android devices, or modified the firmware by gaining physical access to victims&#8217; devices,&#8221; Kaspersky researcher <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.kaspersky.com\/blog\/new-spy-for-android-smartphones-lianspy\/51923\/\" rel=\"noopener\">Dmitry Kalinin wrote in a blog post<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> this week. &#8220;It remains unclear which vulnerability the attackers might have exploited in the former scenario.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">LianSpy is the latest in a fast-growing list of spyware tools. The list includes widely deployed products such as the <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/nso-group-back-business-3-new-ios-zero-click-exploits\" rel=\"noopener\">NSO Group&#8217;s<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> Pegasus Software and the <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/endpoint-security\/operation-behind-predator-mobile-spyware-industrial-scale\" rel=\"noopener\">Intellexa alliance&#8217;s Predator.<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> Researchers have discovered these malware instances targeting iPhone and Android smartphone users in recent years. The main purchasers \u2014 and users \u2014 of these tools are typically governments and intelligence agencies that want to spy on dissidents, political opponents and other persons of interest to them.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In many instances \u2014 as was the case with last year&#8217;s <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/application-security\/operation-triangulation-spyware-attackers-bypass-iphone-memory-protections\" rel=\"noopener\">Operation Triangulation<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> iOS spyware campaign \u2014 the purveyors of mobile spyware tools have exploited zero-day flaws in Android and iOS to deliver and\/or run their malware on target devices. In other instances, including one involving an Android spyware tool dubbed <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/china-group-spreads-android-spyware-via-trojan-signal-telegram-apps\" rel=\"noopener\">BadBazaar<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> last year and another espionage tool dubbed <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/mobile-security\/cyber-threat-actor-booby-trapped-vpn-app-deploy-android-spyware\" rel=\"noopener\">SandStrike<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> in 2022, threat actors have distributed spyware via fake versions of popular applications on official mobile app stores.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"A Three Year Campaign\">A Three Year Campaign<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Kaspersky researchers first stumbled on LianSpy in March 2024 and quickly determined that the entity behind it has been using the spyware tool since July 2021. Their analysis reveals that the attackers are likely distributing the malware disguised as systems applications and financial applications.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Unlike some so-called <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/application-security\/nso-group-adds-mms-fingerprinting-zero-click-attack-spyware-arsenal\" rel=\"noopener\">zero-click spyware tools<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, LianSpy&#8217;s ability to function depends, to a certain extent, on user interaction. &nbsp;When launched, the malware first checks to see if it has the required permissions to execute its mission on the victim&#8217;s device. If it does not have the required permissions, the malware prompts the user to provide them. When LianSpy obtains permission, it registers what is known as an Android Broadcast Receiver to receive and respond to system events such as booting, low battery, and network changes.&nbsp;Kaspersky researchers found LianSpy is using super user binary with a modified name (&#8220;mu&#8221; instead of &#8220;su&#8221;) to try and gain root access on a victim device. Kaspersky officials say this as an indication that the threat actor delivered the malware after first gaining access to the device another way.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Upon launch, the malware hides its icon on the home screen and operates in the background using root privileges,&#8221; Kalinin wrote. &#8220;This allows it to bypass Android status bar notifications, which would typically alert the victim that the smartphone is actively using the camera or microphone.&#8221;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Data Harvesting and Exfiltration\">Data Harvesting and Exfiltration<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">LianSpy&#8217;s primary function is to quietly monitor user activity by intercepting call logs, recording the device screen especially when the user is sending or receiving messages and enumerating all installed apps on the victim device. The threat actor behind the malware has not used private infrastructure for communicating with the malware or storing harvested data. Instead, the attacker has been using public cloud platforms and pastebin services for these functions.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;The threat actor leverages Yandex Disk for both exfiltrating stolen data and storing configuration commands. Victim data is uploaded into a separate Yandex Disk folder,&#8221; Kaspersky said in a <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"http:\/\/By%20Jaikumar%20Vijayan%20%20%20%20For%20the%20past%20three%20years%20at%20least,%20an%20unknown\u2014and%20likely%20state-sponsored\u2014threat%20actor%20has%20been%20using%20a%20previously%20unseen%20mobile%20spyware%20tool%20to%20spy%20on%20an%20unknown%20number%20of%20Android%20smartphone%20users.%20%20%20%20Up%20to%20now,%20the%20campaign%20has%20focused%20mainly%20on%20targeted%20individuals%20in%20Russia,%20according%20to%20researchers%20at%20Kaspersky%20who%20are%20tracking%20the%20threat%20as%20LianSpy.%20But%20the%20tactics%20that%20the%20spyware%20operators%20have%20used%20in%20deploying%20and%20using%20the%20malware%20could%20be%20easily%20applied%20in%20other%20geographies%20as%20well,%20Kaspersky%20said.%20%20%20%20%22LianSpy%20is%20a%20post-exploitation%20Trojan,%20meaning%20that%20the%20attackers%20either%20exploited%20vulnerabilities%20to%20root%20Android%20devices,%20or%20modified%20the%20firmware%20by%20gaining%20physical%20access%20to%20victims\u2019%20devices,%22%20Kaspersky%20researcher%20Dmitry%20Kalinin%20wrote%20in%20a%20blog%20this%20week.%20%22It%20remains%20unclear%20which%20vulnerability%20the%20attackers%20might%20have%20exploited%20in%20the%20former%20scenario.%22%20%20%20%20LianSpy%20is%20the%20latest%20in%20a%20quickly%20growing%20list%20of%20spyware%20tools\u2014that%20includes%20widely%20deployed%20products%20such%20as%20the%20NSO%20Group's%20Pegasus%20Software%20and%20the%20Intellexa%20alliance's%20Predator\u2014which%20researchers%20have%20discovered%20in%20recent%20years%20targeting%20users%20of%20iPhone%20and%20Android%20smartphones.%20The%20main%20purchasers\u2014and%20users\u2014of%20these%20tools%20have%20typically%20been%20governments%20and%20intelligence%20agencies%20that%20want%20to%20spy%20on%20dissidents,%20political%20opponents%20and%20other%20persons%20of%20interest%20to%20them.%20%20%20%20In%20many%20instances\u2014as%20was%20the%20case%20with%20last%20year's%20Operation%20Triangulation%20iOS%20spyware%20campaign\u2014the%20purveyors%20of%20mobile%20spyware%20tools%20have%20exploited%20zero-day%20flaws%20in%20Android%20and%20iOS%20to%20deliver%20and\/or%20run%20their%20malware%20on%20target%20devices.%20In%20other%20instances,%20including%20one%20involving%20an%20Android%20spyware%20tool%20dubbed%20BadBazaar%20last%20year%20and%20another%20espionage%20tool%20dubbed%20SandStrike%20in%202022%20threat%20actors%20have%20distributed%20spyware%20via%20fake%20versions%20of%20popular%20applications%20on%20official%20mobile%20app%20stores.%20%20%20%20Kaspersky%20researchers%20first%20stumbled%20on%20LianSpy%20in%20Match%202024%20and%20quickly%20determined%20that%20the%20entity%20behind%20it%20has%20been%20using%20the%20spyware%20tool%20since%20July%202021.%20Their%20analysis%20showed%20that%20the%20attackers%20are%20likely%20distributing%20the%20malware%20disguised%20as%20systems%20applications%20and%20financial%20applications.%20%20%20%20%20Unlike%20some%20so-called%20zero-click%20spyware%20tools,%20LianSpy%20ability%20to%20function%20depends%20to%20a%20certain%20extent%20on%20user%20interaction.%20%20When%20launched%20the%20malware%20first%20checks%20to%20see%20if%20it%20has%20the%20requisite%20permissions%20to%20execute%20its%20mission%20on%20the%20victim%20device.%20If%20it%20does%20not%20have%20the%20required%20permissions,%20the%20malware%20prompts%20the%20user%20for%20them.%20When%20LianSpy%20obtains%20permission,%20it%20registers%20what%20is%20known%20as%20an%20Android%20Broadcast%20Receiver%20to%20receive%20and%20respond%20to%20system%20events%20such%20as%20booting,%20low%20battery%20and%20network%20changes.%20%20Kaspersky%20researchers%20found%20LianSpy%20to%20be%20using%20a%20super%20user%20binary%20with%20a%20modified%20name%20('mu'%20instead%20of%20'su')%20to%20try%20and%20gain%20root%20access%20on%20a%20victim%20device.%20%20The%20security%20vendor%20assessed%20this%20as%20an%20indication%20that%20the%20threat%20actor%20delivered%20the%20malware%20after%20first%20gaining%20access%20to%20the%20device%20some%20other%20way.%20%20%20%20%22Upon%20launch,%20the%20malware%20hides%20its%20icon%20on%20the%20home%20screen%20and%20operates%20in%20the%20background%20using%20root%20privileges,%22%20Kalinin%20wrote.%20%22This%20allows%20it%20to%20bypass%20Android%20status%20bar%20notifications,%20which%20would%20typically%20alert%20the%20victim%20that%20the%20smartphone%20is%20actively%20using%20the%20camera%20or%20microphone.%22%20%20%20%20%20LianSpy's%20primary%20function%20is%20to%20quietly%20monitor%20user%20activity%20by,%20among%20other%20things,%20intercepting%20call%20logs,%20recording%20the%20device%20screen%20especially%20when%20the%20user%20is%20sending%20or%20receiving%20messages%20and%20enumerating%20all%20installed%20apps%20on%20the%20victim%20device.%20The%20threat%20actor%20behind%20the%20malware%20has%20eschewed%20the%20use%20of%20any%20private%20infrastructure%20for%20either%20communicating%20with%20the%20malware%20or%20storing%20harvested%20data.%20Instead,%20the%20attacker%20has%20been%20using%20public%20cloud%20platforms%20and%20pastebin%20services%20for%20these%20functions.%20%22The%20threat%20actor%20leverages%20Yandex%20Disk%20for%20both%20exfiltrating%20stolen%20data%20and%20storing%20configuration%20commands.%20Victim%20data%20is%20uploaded%20into%20a%20separate%20Yandex%20Disk%20folder,%22%20Kaspersky%20said.%20%20%20%20One%20interesting%20aspect%20about%20LianSpy,%20according%20to%20Kaspersky,%20is%20how%20the%20malware%20uses%20its%20root%20privileges%20on%20a%20compromised%20device.%20Instead%20of%20using%20its%20superuser%20status%20to%20take%20complete%20control%20of%20a%20device,%20LianSpy%20uses%20just%20enough%20of%20all%20the%20functionality%20available%20to%20carry%20out%20its%20mission%20in%20a%20completely%20quiet%20fashion.%20%22Interestingly,%20root%20privileges%20are%20used%20so%20as%20to%20prevent%20their%20detection%20by%20security%20solutions,%22%20the%20security%20vendor%20said.%20Kaspersky%20researchers%20also%20found%20LianSpy%20to%20be%20using%20both%20symmetric%20and%20asymmetric%20keys%20for%20encrypting%20data%20it%20exfiltrates%20makes%20victim%20identification%20impossible,%20%20%20%20%22Beyond%20standard%20espionage%20tactics%20like%20harvesting%20call%20logs%20and%20app%20lists,%20it%20leverages%20root%20privileges%20for%20covert%20screen%20recording%20and%20evasion,%22%20Kalinin%20said.%20%22Unlike%20financially%20motivated%20spyware,%20LianSpy\u2019s%20focus%20on%20capturing%20instant%20message%20content%20indicates%20a%20targeted%20data-gathering%20operation.%22\" rel=\"noopener\">technical writeup<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> on the malware.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">One interesting aspect about LianSpy, according to Kaspersky, is how the malware uses its root privileges on a compromised device. Instead of using its superuser status to take complete control of a device, LianSpy uses just enough of the functionality available to carry out its mission in a quiet fashion. &#8220;Interestingly, root privileges are used so as to prevent their detection by security solutions,&#8221; the security vendor says. Kaspersky researchers also found LianSpy to be using both symmetric and asymmetric keys for encrypting the data it exfiltrates, which makes victim identification impossible.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Beyond standard espionage tactics like harvesting call logs and app lists, it leverages root privileges for covert screen recording and evasion,&#8221; Kalinin said. &#8220;Unlike financially motivated spyware, LianSpy&#8217;s focus on capturing instant message content indicates a targeted data-gathering operation.&#8221;<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/mobile-security\/sophisticated-android-spyware-targets-users-in-russia\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>An unknown \u2014 and likely state-sponsored \u2014 threat actor has<\/p>\n","protected":false},"author":12,"featured_media":4642,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-4641","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/sophisticated-android-spyware-targets-users-in-russia.jpg?fit=1920%2C1080&ssl=1",1920,1080,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/sophisticated-android-spyware-targets-users-in-russia.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/sophisticated-android-spyware-targets-users-in-russia.jpg?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/sophisticated-android-spyware-targets-users-in-russia.jpg?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/sophisticated-android-spyware-targets-users-in-russia.jpg?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/sophisticated-android-spyware-targets-users-in-russia.jpg?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/sophisticated-android-spyware-targets-users-in-russia.jpg?fit=1920%2C1080&ssl=1",1920,1080,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/sophisticated-android-spyware-targets-users-in-russia.jpg?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/sophisticated-android-spyware-targets-users-in-russia.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/sophisticated-android-spyware-targets-users-in-russia.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/sophisticated-android-spyware-targets-users-in-russia.jpg?fit=1920%2C1080&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4641","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=4641"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4641\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/4642"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=4641"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=4641"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=4641"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}