ResidentBat: Belarusian KGB Android Spyware at Internet Scale
ID: f89783e9-adc0-5e6b-bfe2-c11f66cb62fd
STIX ID: report--f89783e9-adc0-5e6b-bfe2-c11f66cb62fd
Feed Name: Censys Blog
Date Published: 2026-02-24
Date Updated: 2026-04-27
Author: Kate Lake; Aidan Holland; Senior Security Researcher
ResidentBat is an Android spyware implant attributed to the Belarusian KGB that requires physical access and ADB sideloading to install and provides operators with SMS/call/messenger exfiltration, microphone and screen capture, file access, remote commands, and a remote wipe capability. The report details C2 infrastructure fingerprints (self-signed certificates with CN=server, banner_hash_sha256, and a concentrated port range 7000–7257 and 4022), observed hosting geography, operational context against journalists/activists, and recommended network- and device-based detection and mitigation strategies.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
