logo

ResidentBat: Belarusian KGB Android Spyware at Internet Scale

ID: f89783e9-adc0-5e6b-bfe2-c11f66cb62fd

STIX ID: report--f89783e9-adc0-5e6b-bfe2-c11f66cb62fd

Feed Name: Censys Blog

Threat Score
78/100

Date Published: 2026-02-24

Date Updated: 2026-04-27

Author: Kate Lake; Aidan Holland; Senior Security Researcher

...
...

ResidentBat is an Android spyware implant attributed to the Belarusian KGB that requires physical access and ADB sideloading to install and provides operators with SMS/call/messenger exfiltration, microphone and screen capture, file access, remote commands, and a remote wipe capability. The report details C2 infrastructure fingerprints (self-signed certificates with CN=server, banner_hash_sha256, and a concentrated port range 7000–7257 and 4022), observed hosting geography, operational context against journalists/activists, and recommended network- and device-based detection and mitigation strategies.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.