logo

Android spyware trojan targets Russian military personnel who use Alpine Quest mapping software

ID: 579f7f08-130c-5a7c-b952-3bf601575bc0

STIX ID: report--579f7f08-130c-5a7c-b952-3bf601575bc0

Feed Name: Dr.Web News

Threat Score
72/100

Date Published: 2025-04-21

Date Updated: 2026-04-27

...
...

**Android.Spy.1292.origin** is spyware embedded into a trojanized Alpine Quest app distributed via a fake Telegram channel and a Russian app catalog; it harvests phone numbers, contacts, geolocation, file listings and can download modules to exfiltrate Telegram/WhatsApp files and Alpine Quest location logs, with observed targeting of Russian military personnel.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.