Russian cyberspies target Android users with new spyware

Share:

Russian cyberspies Gamaredon has been discovered using two Android spyware families named ‘BoneSpy’ and ‘PlainGnome’ to spy on and steal data from mobile devices.

According to Lookout, which discovered the two malware families, BoneSpy has been active since 2021, while PlainGnome emerged in 2024. Both target Russian-speaking individuals in former Soviet states.

Gamaredon (aka “Shuckworm”) is believed to be part of Russia’s Federal Security Agency (FSB), and its operations are closely tied to the country’s national geopolitical interests.

 

Although the threat group has used various malware tools, BoneSpy and PlainGnome are the first documented cases of Gamaredon malware targeting mobile devices, specifically Android.

From open-source to custom malware
BoneSpy, typically delivered via trojanized Telegram apps or by impersonating Samsung Knox, was based on the open-source ‘DroidWatcher’ surveillance app, which dates back to 2013.

Impersonating the Samsung Knox Manager
Impersonating the Samsung Knox Manager
Source: BleepingComputer
Lookout says development work on BoneSpy peaked between January and October 2022, stabilizing to the following capabilities:

Collects SMS messages, including sender, content, and timestamps
Records ambient audio and phone call conversations
Captures GPS and cell-based location data
Takes pictures using the camera and captures device screenshots
Accesses user’s web browsing history
Extracts names, numbers, emails, and call details from the contact list and call logs
Accesses clipboard content
Reads device notifications
PlainGnome is a newer, custom Android surveillance malware that does not use the codebase of a previously known project. Lookout observed significant evolution in its code from January to October this year, indicating active development.

The new malware uses a two-stage installation process separating the dropper and payload, which makes it stealthier and more versatile.

PlainGnome features all the data collection capabilities of BoneSpy but also integrates advanced features like Jetpack WorkManager to exfiltrate data only when the device is idle, reducing detection risks.

The malware supports a recording mode that activates only when the device is idle and the screen is off to avoid tipping off victims through microphone activation indicators that they are being spied on.

Despite the increased sophistication in surveillance operations, Lookout notes that the spyware does not currently feature any form of code obfuscation, so analysis quickly revealed its true nature.

Upon launch, it requests the approval of dangerous permissions like access to SMS, contacts, call logs, and cameras. However, given its masking as a communication app, victims may be tricked into approving the request.

Lookout notes that neither BoneSpy nor PlainGnome were ever found on Google Play, so they’re most likely downloaded from websites victims are directed to following social engineering. This approach matches Gamaredon’s narrow targeting scope.

The researcher’s report highlights Gamaredon’s increasing focus on Android devices, showcasing the group’s evolving tactics to expand its surveillance capabilities to mobile devices, which are increasingly used in all aspects of our lives and making them valuable targets.

Google has confirmed to BleepingComputer that Google Play Protect automatically protects against known versions of this malware.

Bill Toulas

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
7:15 am, Jun 17, 2025
weather icon 17°C
L: 14° | H: 17°
broken clouds
Humidity: 76 %
Pressure: 1026 mb
Wind: 6 mph SSW
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 75%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:42 am
Sunset: 9:20 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
14° | 17°°C 0 mm 0% 10 mph 70 % 1026 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
15° | 27°°C 0 mm 0% 10 mph 77 % 1026 mb 0 mm/h
Thu Jun 19 10:00 pm
weather icon
17° | 28°°C 0 mm 0% 10 mph 73 % 1027 mb 0 mm/h
Fri Jun 20 10:00 pm
weather icon
16° | 25°°C 0 mm 0% 11 mph 70 % 1027 mb 0 mm/h
Sat Jun 21 10:00 pm
weather icon
16° | 29°°C 0 mm 0% 12 mph 75 % 1024 mb 0 mm/h
Today 10:00 am
weather icon
18° | 20°°C 0 mm 0% 7 mph 70 % 1026 mb 0 mm/h
Today 1:00 pm
weather icon
22° | 25°°C 0 mm 0% 8 mph 48 % 1025 mb 0 mm/h
Today 4:00 pm
weather icon
27° | 27°°C 0 mm 0% 8 mph 33 % 1024 mb 0 mm/h
Today 7:00 pm
weather icon
25° | 25°°C 0 mm 0% 10 mph 43 % 1024 mb 0 mm/h
Today 10:00 pm
weather icon
20° | 20°°C 0 mm 0% 8 mph 55 % 1025 mb 0 mm/h
Tomorrow 1:00 am
weather icon
17° | 17°°C 0 mm 0% 5 mph 69 % 1025 mb 0 mm/h
Tomorrow 4:00 am
weather icon
15° | 15°°C 0 mm 0% 3 mph 77 % 1025 mb 0 mm/h
Tomorrow 7:00 am
weather icon
17° | 17°°C 0 mm 0% 3 mph 73 % 1025 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€92,705.91
0.53%
Ethereum(ETH)
€2,232.53
-1.07%
Tether(USDT)
€0.87
0.02%
XRP(XRP)
€1.94
2.58%
Solana(SOL)
€133.01
-1.89%
USDC(USDC)
€0.87
0.00%
Dogecoin(DOGE)
€0.150384
-2.09%
Shiba Inu(SHIB)
€0.000010
-2.11%
Pepe(PEPE)
€0.000010
-6.86%
Scroll to Top