logo

ResidentBat Android Malware Provides Belarusian KGB with Persistent Access to Mobile Devices

ID: 30b6993b-823e-580e-a103-93bceb3ec66b

STIX ID: report--30b6993b-823e-580e-a103-93bceb3ec66b

Feed Name: cybersecurityNews.com

Threat Score
88/100

Date Published: 2026-02-26

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

ResidentBat is a targeted Android spyware campaign attributed to the Belarusian KGB that uses hands-on ADB sideloading to install an APK with extensive espionage capabilities (SMS/calls, microphone, screenshots, file access, interception of encrypted messaging) and remote wipe functionality; its C2 infrastructure is hardened and uses self-signed TLS certs (CN=server) on ports 7000–7257 with anti-forensics behaviors (catch-all 200 OK, static Date) and client-certificate allowlisting to evade detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.