logo

Android backdoor spies on employees of Russian businesses

ID: a633c1a4-5ba7-5ad2-b40f-3b99b01e33a7

STIX ID: report--a633c1a4-5ba7-5ad2-b40f-3b99b01e33a7

Feed Name: Dr.Web News

Threat Score
78/100

Date Published: 2025-08-20

Date Updated: 2026-04-27

...
...

Doctor Web reports Android.Backdoor.916.origin, a targeted Android backdoor active since January 2025 that masquerades as a Russian-themed antivirus app to trick Russian business users into installing an APK; it requests extensive permissions and leverages Accessibility and device-admin capabilities to persist, record audio/video/screen, keylog, and exfiltrate SMS, contacts, call history, geolocation and media to multiple C2 servers, with published IoCs and detection/removal guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.