logo

New Android spyware found on phone seized by Russian FSB

ID: 2e26e692-ef25-54cd-86f5-c17619356619

STIX ID: report--2e26e692-ef25-54cd-86f5-c17619356619

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2024-12-05

Date Updated: 2026-03-27

Author: Bill Toulas

...
...

Citizen Lab forensic analysis found that a Russian programmer's phone, returned after detention by the FSB, had been implanted with advanced spyware that impersonated a legitimate Android call‑recorder app. The Monokle-like malware grants broad permissions (location, SMS/contacts/calendar access, call/screen/video recording, keylogging, file and password exfiltration, remote command execution and APK installation), uses a two-stage encrypted architecture, and shows indicators of reuse or evolution of Monokle code with potential iOS targeting—consistent with state-sponsored surveillance operations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.