logo

Experts discovered the first mobile malware families linked to Russia’s Gamaredon

ID: aa95d9ee-f4ba-5679-a2e9-ea5a2e1e3921

STIX ID: report--aa95d9ee-f4ba-5679-a2e9-ea5a2e1e3921

Feed Name: Security Affairs

Threat Score
85/100

Date Published: 2024-12-13

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Lookout researchers attributed two Android surveillance families — BoneSpy (in use since 2021) and PlainGnome (first seen in 2024) — to the Russian APT Gamaredon. Both families exfiltrate SMS, call logs, call audio, photos, location and contacts; BoneSpy appears derived from the open-source DroidWatcher, while PlainGnome is a two-stage dropper. Infrastructure overlap (shared IPs, domain naming, dynamic DNS) and Russian-language targeting link these mobile tools to Gamaredon’s long-running cyber-espionage campaigns against Russian-speaking victims in former Soviet states.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.