Experts discovered the first mobile malware families linked to Russia’s Gamaredon
ID: aa95d9ee-f4ba-5679-a2e9-ea5a2e1e3921
STIX ID: report--aa95d9ee-f4ba-5679-a2e9-ea5a2e1e3921
Feed Name: Security Affairs
Lookout researchers attributed two Android surveillance families — BoneSpy (in use since 2021) and PlainGnome (first seen in 2024) — to the Russian APT Gamaredon. Both families exfiltrate SMS, call logs, call audio, photos, location and contacts; BoneSpy appears derived from the open-source DroidWatcher, while PlainGnome is a two-stage dropper. Infrastructure overlap (shared IPs, domain naming, dynamic DNS) and Russian-language targeting link these mobile tools to Gamaredon’s long-running cyber-espionage campaigns against Russian-speaking victims in former Soviet states.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
