Russian cyberspies target Android users with new spyware

Share:

Russian cyberspies Gamaredon has been discovered using two Android spyware families named ‘BoneSpy’ and ‘PlainGnome’ to spy on and steal data from mobile devices.

According to Lookout, which discovered the two malware families, BoneSpy has been active since 2021, while PlainGnome emerged in 2024. Both target Russian-speaking individuals in former Soviet states.

Gamaredon (aka “Shuckworm”) is believed to be part of Russia’s Federal Security Agency (FSB), and its operations are closely tied to the country’s national geopolitical interests.

 

Although the threat group has used various malware tools, BoneSpy and PlainGnome are the first documented cases of Gamaredon malware targeting mobile devices, specifically Android.

From open-source to custom malware
BoneSpy, typically delivered via trojanized Telegram apps or by impersonating Samsung Knox, was based on the open-source ‘DroidWatcher’ surveillance app, which dates back to 2013.

Impersonating the Samsung Knox Manager
Impersonating the Samsung Knox Manager
Source: BleepingComputer
Lookout says development work on BoneSpy peaked between January and October 2022, stabilizing to the following capabilities:

Collects SMS messages, including sender, content, and timestamps
Records ambient audio and phone call conversations
Captures GPS and cell-based location data
Takes pictures using the camera and captures device screenshots
Accesses user’s web browsing history
Extracts names, numbers, emails, and call details from the contact list and call logs
Accesses clipboard content
Reads device notifications
PlainGnome is a newer, custom Android surveillance malware that does not use the codebase of a previously known project. Lookout observed significant evolution in its code from January to October this year, indicating active development.

The new malware uses a two-stage installation process separating the dropper and payload, which makes it stealthier and more versatile.

PlainGnome features all the data collection capabilities of BoneSpy but also integrates advanced features like Jetpack WorkManager to exfiltrate data only when the device is idle, reducing detection risks.

The malware supports a recording mode that activates only when the device is idle and the screen is off to avoid tipping off victims through microphone activation indicators that they are being spied on.

Despite the increased sophistication in surveillance operations, Lookout notes that the spyware does not currently feature any form of code obfuscation, so analysis quickly revealed its true nature.

Upon launch, it requests the approval of dangerous permissions like access to SMS, contacts, call logs, and cameras. However, given its masking as a communication app, victims may be tricked into approving the request.

Lookout notes that neither BoneSpy nor PlainGnome were ever found on Google Play, so they’re most likely downloaded from websites victims are directed to following social engineering. This approach matches Gamaredon’s narrow targeting scope.

The researcher’s report highlights Gamaredon’s increasing focus on Android devices, showcasing the group’s evolving tactics to expand its surveillance capabilities to mobile devices, which are increasingly used in all aspects of our lives and making them valuable targets.

Google has confirmed to BleepingComputer that Google Play Protect automatically protects against known versions of this malware.

Bill Toulas

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
1:19 pm, Jun 17, 2025
weather icon 25°C
L: 24° | H: 26°
scattered clouds
Humidity: 50 %
Pressure: 1025 mb
Wind: 8 mph SW
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 42%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:42 am
Sunset: 9:20 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
24° | 26°°C 0 mm 0% 10 mph 53 % 1025 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
15° | 26°°C 0 mm 0% 8 mph 76 % 1026 mb 0 mm/h
Thu Jun 19 10:00 pm
weather icon
16° | 27°°C 0 mm 0% 11 mph 82 % 1028 mb 0 mm/h
Fri Jun 20 10:00 pm
weather icon
15° | 25°°C 0 mm 0% 11 mph 71 % 1028 mb 0 mm/h
Sat Jun 21 10:00 pm
weather icon
15° | 28°°C 0 mm 0% 10 mph 79 % 1026 mb 0 mm/h
Today 4:00 pm
weather icon
25° | 26°°C 0 mm 0% 8 mph 45 % 1025 mb 0 mm/h
Today 7:00 pm
weather icon
24° | 24°°C 0 mm 0% 10 mph 44 % 1024 mb 0 mm/h
Today 10:00 pm
weather icon
19° | 19°°C 0 mm 0% 8 mph 53 % 1025 mb 0 mm/h
Tomorrow 1:00 am
weather icon
16° | 16°°C 0 mm 0% 5 mph 67 % 1025 mb 0 mm/h
Tomorrow 4:00 am
weather icon
15° | 15°°C 0 mm 0% 4 mph 76 % 1025 mb 0 mm/h
Tomorrow 7:00 am
weather icon
17° | 17°°C 0 mm 0% 3 mph 72 % 1025 mb 0 mm/h
Tomorrow 10:00 am
weather icon
21° | 21°°C 0 mm 0% 5 mph 53 % 1025 mb 0 mm/h
Tomorrow 1:00 pm
weather icon
25° | 25°°C 0 mm 0% 8 mph 42 % 1025 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€91,431.59
-0.93%
Ethereum(ETH)
€2,209.39
-2.09%
Tether(USDT)
€0.86
0.01%
XRP(XRP)
€1.91
-2.55%
Solana(SOL)
€130.70
-3.21%
USDC(USDC)
€0.86
0.00%
Dogecoin(DOGE)
€0.148661
-2.65%
Shiba Inu(SHIB)
€0.000010
-3.31%
Pepe(PEPE)
€0.000009
-7.19%
Scroll to Top