Russian cyberspies target Android users with new spyware
ID: a91d8aa6-7a4c-5156-b5df-47baf6ffbaea
STIX ID: report--a91d8aa6-7a4c-5156-b5df-47baf6ffbaea
Feed Name: Bleeping Computer
Lookout researchers attribute two Android surveillanceware families—BoneSpy (based on the open-source DroidWatcher, active since 2021) and PlainGnome (custom, observed in 2024)—to the Russian APT Gamaredon; both spyware families target Russian-speaking individuals in former Soviet states, collect SMS, calls/audio, location, camera images/screenshots, contacts, clipboard and browsing history, and are delivered via trojanized Telegram apps or Samsung Knox impersonation while using permission-based social engineering and stealthy exfiltration techniques.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
