Sophisticated Android Spyware Targets Users in Russia
ID: 75a82d32-6ab5-5970-bdc1-c745abda5031
STIX ID: report--75a82d32-6ab5-5970-bdc1-c745abda5031
Feed Name: Dark Reading
Researchers at Kaspersky discovered LianSpy, a previously unknown Android post-exploitation spyware used since July 2021 in a targeted espionage campaign likely run by a state-sponsored actor; the malware obtains root (using a modified superuser binary), hides its UI, records screens and harvests call logs and app data, and exfiltrates stolen data via public cloud services (notably Yandex Disk), demonstrating a sophisticated, stealthy capability focused on instant-message and user-activity collection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
