ResidentBat Android Malware Grants Belarusian KGB Ongoing Mobile Access
ID: 77416477-14ed-53ea-aa10-710fb2d53f28
STIX ID: report--77416477-14ed-53ea-aa10-710fb2d53f28
Feed Name: GBHackers
ResidentBat is a custom Android spyware implant attributed to the Belarusian KGB that is sideloaded via ADB during hands‑on device seizures to convert phones into persistent surveillance platforms; it collects SMS, call logs, microphone audio, screen captures, messenger content, local files, and supports remote factory wipes. The report documents deployment flow, C2 fingerprints (self‑signed TLS CN=server, ports 7000–7257 and 4022, stable banner hash), known infrastructure and geolocation, published APK hashes, and recommended mitigations (disable USB debugging/sideloading, monitor ADB usage, enable Play Protect/Advanced Protection).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
