logo

Corporate Leaders Targeted by Android Spyware Masquerading as Security Apps

ID: fa006e05-dc36-51f5-9013-08cbcaad18a1

STIX ID: report--fa006e05-dc36-51f5-9013-08cbcaad18a1

Feed Name: Cyber Press

Threat Score
75/100

Date Published: 2025-08-25

Date Updated: 2026-04-19

Author: Priya

...
...

Doctor Web uncovered a targeted Android spyware campaign (Android.Backdoor.916.origin, aka GuardCB) that impersonates official security or FSB-branded apps and is distributed via sideloaded APKs in private messages to Russian business leaders. The malware obtains broad permissions including Accessibility Service and device admin to persistently exfiltrate SMS, contacts, call logs, media and location, and supports live audio, video and screen streaming; researchers classify it as a focused cyber-espionage operation and advise restricting APK side-loading and improving mobile security for high-risk users.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.