Russian cyberspies target Android users with new spyware

Share:

Russian cyberspies Gamaredon has been discovered using two Android spyware families named ‘BoneSpy’ and ‘PlainGnome’ to spy on and steal data from mobile devices.

According to Lookout, which discovered the two malware families, BoneSpy has been active since 2021, while PlainGnome emerged in 2024. Both target Russian-speaking individuals in former Soviet states.

Gamaredon (aka “Shuckworm”) is believed to be part of Russia’s Federal Security Agency (FSB), and its operations are closely tied to the country’s national geopolitical interests.

 

Although the threat group has used various malware tools, BoneSpy and PlainGnome are the first documented cases of Gamaredon malware targeting mobile devices, specifically Android.

From open-source to custom malware
BoneSpy, typically delivered via trojanized Telegram apps or by impersonating Samsung Knox, was based on the open-source ‘DroidWatcher’ surveillance app, which dates back to 2013.

Impersonating the Samsung Knox Manager
Impersonating the Samsung Knox Manager
Source: BleepingComputer
Lookout says development work on BoneSpy peaked between January and October 2022, stabilizing to the following capabilities:

Collects SMS messages, including sender, content, and timestamps
Records ambient audio and phone call conversations
Captures GPS and cell-based location data
Takes pictures using the camera and captures device screenshots
Accesses user’s web browsing history
Extracts names, numbers, emails, and call details from the contact list and call logs
Accesses clipboard content
Reads device notifications
PlainGnome is a newer, custom Android surveillance malware that does not use the codebase of a previously known project. Lookout observed significant evolution in its code from January to October this year, indicating active development.

The new malware uses a two-stage installation process separating the dropper and payload, which makes it stealthier and more versatile.

PlainGnome features all the data collection capabilities of BoneSpy but also integrates advanced features like Jetpack WorkManager to exfiltrate data only when the device is idle, reducing detection risks.

The malware supports a recording mode that activates only when the device is idle and the screen is off to avoid tipping off victims through microphone activation indicators that they are being spied on.

Despite the increased sophistication in surveillance operations, Lookout notes that the spyware does not currently feature any form of code obfuscation, so analysis quickly revealed its true nature.

Upon launch, it requests the approval of dangerous permissions like access to SMS, contacts, call logs, and cameras. However, given its masking as a communication app, victims may be tricked into approving the request.

Lookout notes that neither BoneSpy nor PlainGnome were ever found on Google Play, so they’re most likely downloaded from websites victims are directed to following social engineering. This approach matches Gamaredon’s narrow targeting scope.

The researcher’s report highlights Gamaredon’s increasing focus on Android devices, showcasing the group’s evolving tactics to expand its surveillance capabilities to mobile devices, which are increasingly used in all aspects of our lives and making them valuable targets.

Google has confirmed to BleepingComputer that Google Play Protect automatically protects against known versions of this malware.

Bill Toulas

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
10:45 pm, Apr 22, 2025
weather icon 10°C
L: 9° | H: 11°
broken clouds
Humidity: 78 %
Pressure: 1015 mb
Wind: 8 mph SSW
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 77%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 5:49 am
Sunset: 8:07 pm
DailyHourly
Daily ForecastHourly Forecast
Tomorrow 10:00 pm
weather icon
9° | 11°°C 1 mm 100% 13 mph 93 % 1018 mb 0 mm/h
Thu Apr 24 10:00 pm
weather icon
7° | 16°°C 0.2 mm 20% 6 mph 85 % 1023 mb 0 mm/h
Fri Apr 25 10:00 pm
weather icon
8° | 17°°C 0 mm 0% 9 mph 84 % 1024 mb 0 mm/h
Sat Apr 26 10:00 pm
weather icon
9° | 16°°C 0.99 mm 99% 6 mph 89 % 1024 mb 0 mm/h
Sun Apr 27 10:00 pm
weather icon
9° | 19°°C 0 mm 0% 8 mph 96 % 1025 mb 0 mm/h
Tomorrow 1:00 am
weather icon
10° | 10°°C 0 mm 0% 7 mph 78 % 1015 mb 0 mm/h
Tomorrow 4:00 am
weather icon
8° | 9°°C 1 mm 100% 9 mph 89 % 1012 mb 0 mm/h
Tomorrow 7:00 am
weather icon
8° | 8°°C 1 mm 100% 13 mph 93 % 1009 mb 0 mm/h
Tomorrow 10:00 am
weather icon
10° | 10°°C 1 mm 100% 10 mph 93 % 1010 mb 0 mm/h
Tomorrow 1:00 pm
weather icon
11° | 11°°C 0.8 mm 80% 9 mph 84 % 1012 mb 0 mm/h
Tomorrow 4:00 pm
weather icon
11° | 11°°C 0.2 mm 20% 11 mph 72 % 1013 mb 0 mm/h
Tomorrow 7:00 pm
weather icon
11° | 11°°C 0 mm 0% 7 mph 73 % 1015 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
9° | 9°°C 0 mm 0% 3 mph 89 % 1018 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€79,591.07
4.83%
Ethereum(ETH)
€1,501.64
9.40%
Tether(USDT)
€0.87
0.03%
XRP(XRP)
€1.90
4.89%
Solana(SOL)
€126.80
6.67%
USDC(USDC)
€0.87
0.00%
Dogecoin(DOGE)
€0.152318
10.45%
Shiba Inu(SHIB)
€0.000011
8.55%
Pepe(PEPE)
€0.000008
10.86%
Scroll to Top