ResidentBat Android Malware Provides Belarusian KGB with Persistent Access to Mobile Devices
ID: 30b6993b-823e-580e-a103-93bceb3ec66b
STIX ID: report--30b6993b-823e-580e-a103-93bceb3ec66b
Feed Name: cybersecurityNews.com
ResidentBat is a targeted Android spyware campaign attributed to the Belarusian KGB that uses hands-on ADB sideloading to install an APK with extensive espionage capabilities (SMS/calls, microphone, screenshots, file access, interception of encrypted messaging) and remote wipe functionality; its C2 infrastructure is hardened and uses self-signed TLS certs (CN=server) on ports 7000–7257 with anti-forensics behaviors (catch-all 200 OK, static Date) and client-certificate allowlisting to evade detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
