Corporate Leaders Targeted by Android Spyware Masquerading as Security Apps
ID: fa006e05-dc36-51f5-9013-08cbcaad18a1
STIX ID: report--fa006e05-dc36-51f5-9013-08cbcaad18a1
Feed Name: Cyber Press
Doctor Web uncovered a targeted Android spyware campaign (Android.Backdoor.916.origin, aka GuardCB) that impersonates official security or FSB-branded apps and is distributed via sideloaded APKs in private messages to Russian business leaders. The malware obtains broad permissions including Accessibility Service and device admin to persistently exfiltrate SMS, contacts, call logs, media and location, and supports live audio, video and screen streaming; researchers classify it as a focused cyber-espionage operation and advise restricting APK side-loading and improving mobile security for high-risk users.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
