logo

New Android Spyware Disguised as an Antivirus Attacking Business Executives

ID: a914497f-0c3c-5e5d-8f77-ddbfe7383e83

STIX ID: report--a914497f-0c3c-5e5d-8f77-ddbfe7383e83

Feed Name: cybersecurityNews.com

Threat Score
72/100

Date Published: 2025-08-25

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

**Android.Backdoor.916.origin ("GuardCB")**: A malicious Android backdoor disguised as an antivirus app and distributed via sideloaded APKs in encrypted messenger threads targeting Russian business executives. Once installed it requests extensive permissions and Accessibility Service privileges to achieve persistence and self-restart, enabling operators to exfiltrate call logs, SMS, contacts, geolocation, images, microphone audio, camera video and screen captures, execute arbitrary shell commands, and resist removal via overlays and admin controls; Dr.Web researchers report active targeted campaigns and list detection/removal of known variants.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.