logo

New LianSpy malware hides by blocking Android security feature

ID: 6d1b9e65-2750-5cc4-b516-523c936c2efe

STIX ID: report--6d1b9e65-2750-5cc4-b516-523c936c2efe

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2024-08-05

Date Updated: 2026-07-17

Author: Bill Toulas

...
...

Kaspersky researchers uncovered LianSpy, a previously undocumented Android spyware active since July 2021 that poses as Alipay or a system service to evade detection, gains root via a modified su/mu binary (likely via a zero-day or physical access), bypasses Android 12+ privacy indicators, suppresses user notifications, captures screenshots and other sensitive data from targeted apps, stores data encrypted locally, and exfiltrates it to Yandex Disk under attacker control; the malware is highly stealthy and focused on Russian targets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.