Russian cyberspies target Android users with new spyware

Share:

Russian cyberspies Gamaredon has been discovered using two Android spyware families named ‘BoneSpy’ and ‘PlainGnome’ to spy on and steal data from mobile devices.

According to Lookout, which discovered the two malware families, BoneSpy has been active since 2021, while PlainGnome emerged in 2024. Both target Russian-speaking individuals in former Soviet states.

Gamaredon (aka “Shuckworm”) is believed to be part of Russia’s Federal Security Agency (FSB), and its operations are closely tied to the country’s national geopolitical interests.

Although the threat group has used various malware tools, BoneSpy and PlainGnome are the first documented cases of Gamaredon malware targeting mobile devices, specifically Android.

From open-source to custom malware

BoneSpy, typically delivered via trojanized Telegram apps or by impersonating Samsung Knox, was based on the open-source ‘DroidWatcher’ surveillance app, which dates back to 2013.

Lookout says development work on BoneSpy peaked between January and October 2022, stabilizing to the following capabilities:

  • Collects SMS messages, including sender, content, and timestamps
  • Records ambient audio and phone call conversations
  • Captures GPS and cell-based location data
  • Takes pictures using the camera and captures device screenshots
  • Accesses user’s web browsing history
  • Extracts names, numbers, emails, and call details from the contact list and call logs
  • Accesses clipboard content
  • Reads device notifications

PlainGnome is a newer, custom Android surveillance malware that does not use the codebase of a previously known project. Lookout observed significant evolution in its code from January to October this year, indicating active development.

The new malware uses a two-stage installation process separating the dropper and payload, which makes it stealthier and more versatile.

PlainGnome features all the data collection capabilities of BoneSpy but also integrates advanced features like Jetpack WorkManager to exfiltrate data only when the device is idle, reducing detection risks.

The malware supports a recording mode that activates only when the device is idle and the screen is off to avoid tipping off victims through microphone activation indicators that they are being spied on.

Despite the increased sophistication in surveillance operations, Lookout notes that the spyware does not currently feature any form of code obfuscation, so analysis quickly revealed its true nature.

Upon launch, it requests the approval of dangerous permissions like access to SMS, contacts, call logs, and cameras. However, given its masking as a communication app, victims may be tricked into approving the request.

Lookout notes that neither BoneSpy nor PlainGnome were ever found on Google Play, so they’re most likely downloaded from websites victims are directed to following social engineering. This approach matches Gamaredon’s narrow targeting scope.

The researcher’s report highlights Gamaredon’s increasing focus on Android devices, showcasing the group’s evolving tactics to expand its surveillance capabilities to mobile devices, which are increasingly used in all aspects of our lives and making them valuable targets.

Google has confirmed to BleepingComputer that Google Play Protect automatically protects against known versions of this malware.

Source

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
11:24 am, Jan 15, 2025
weather icon 9°C
L: 9° | H: 10°
overcast clouds
Humidity: 92 %
Pressure: 1035 mb
Wind: 3 mph WNW
Wind Gust: 6 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 100%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 7:59 am
Sunset: 4:20 pm
DailyHourly
Daily ForecastHourly Forecast
Today 9:00 pm
weather icon
9° | 10°°C 0 mm 0% 3 mph 98 % 1034 mb 0 mm/h
Tomorrow 9:00 pm
weather icon
5° | 9°°C 0 mm 0% 5 mph 96 % 1035 mb 0 mm/h
Fri Jan 17 9:00 pm
weather icon
3° | 7°°C 0 mm 0% 4 mph 93 % 1036 mb 0 mm/h
Sat Jan 18 9:00 pm
weather icon
2° | 7°°C 0 mm 0% 3 mph 89 % 1033 mb 0 mm/h
Sun Jan 19 9:00 pm
weather icon
2° | 6°°C 0 mm 0% 4 mph 89 % 1024 mb 0 mm/h
Today 12:00 pm
weather icon
9° | 9°°C 0 mm 0% 2 mph 92 % 1034 mb 0 mm/h
Today 3:00 pm
weather icon
9° | 9°°C 0 mm 0% 3 mph 91 % 1034 mb 0 mm/h
Today 6:00 pm
weather icon
7° | 8°°C 0 mm 0% 3 mph 96 % 1034 mb 0 mm/h
Today 9:00 pm
weather icon
6° | 6°°C 0 mm 0% 3 mph 98 % 1034 mb 0 mm/h
Tomorrow 12:00 am
weather icon
6° | 6°°C 0 mm 0% 3 mph 96 % 1034 mb 0 mm/h
Tomorrow 3:00 am
weather icon
5° | 5°°C 0 mm 0% 3 mph 95 % 1033 mb 0 mm/h
Tomorrow 6:00 am
weather icon
5° | 5°°C 0 mm 0% 3 mph 96 % 1034 mb 0 mm/h
Tomorrow 9:00 am
weather icon
5° | 5°°C 0 mm 0% 3 mph 96 % 1034 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€93,654.60
0.23%
Ethereum(ETH)
€3,096.32
-0.80%
XRP(XRP)
€2.68
7.28%
Tether(USDT)
€0.97
-0.01%
Solana(SOL)
€180.71
-0.55%
Dogecoin(DOGE)
€0.340522
0.40%
USDC(USDC)
€0.97
0.00%
Shiba Inu(SHIB)
€0.000020
-1.41%
Pepe(PEPE)
€0.000016
-1.87%
Peanut the Squirrel(PNUT)
€0.52
-9.69%
Scroll to Top