logo

Russian cyberspies target Android users with new spyware

ID: a91d8aa6-7a4c-5156-b5df-47baf6ffbaea

STIX ID: report--a91d8aa6-7a4c-5156-b5df-47baf6ffbaea

Feed Name: Bleeping Computer

Threat Score
83/100

Date Published: 2024-12-13

Date Updated: 2026-03-27

Author: Bill Toulas

...
...

Lookout researchers attribute two Android surveillanceware families—BoneSpy (based on the open-source DroidWatcher, active since 2021) and PlainGnome (custom, observed in 2024)—to the Russian APT Gamaredon; both spyware families target Russian-speaking individuals in former Soviet states, collect SMS, calls/audio, location, camera images/screenshots, contacts, clipboard and browsing history, and are delivered via trojanized Telegram apps or Samsung Knox impersonation while using permission-based social engineering and stealthy exfiltration techniques.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.