Table of Contents
  • Home
  • /
  • Blog
  • /
  • Russian Gamaredon APT Deploys New Android Spyware Targeting Former Soviet States
December 13, 2024
|
3m

Russian Gamaredon APT Deploys New Android Spyware Targeting Former Soviet States


Russian APT Gamaredon Launches Android Spyware Attack

The Russia-linked state-sponsored threat actor Gamaredon has been attributed to two new Android spyware tools called BoneSpy and PlainGnome, marking a significant expansion of the group's cyber espionage capabilities into mobile platforms.

Cybersecurity researchers at Lookout have discovered these mobile surveillance tools, which represent the first known mobile-specific malware families associated with the Gamaredon group, also known as Primitive Bear or Shuckworm. The group is believed to be affiliated with Russia's Federal Security Service (FSB).

BoneSpy and PlainGnome are specifically designed to target Russian-speaking victims in former Soviet states, including Uzbekistan, Kazakhstan, Tajikistan, and Kyrgyzstan. The targeting is likely related to the deteriorating relations between these countries and Russia since the invasion of Ukraine.

Both spyware tools demonstrate extensive surveillance capabilities, collecting a wide range of sensitive information from infected devices. Their data collection features include:

  • SMS messages

  • Call logs

  • Phone call audio recordings

  • Device location tracking

  • Contact lists

  • Photos from device cameras

  • Browser history

  • Device information

BoneSpy, which has been operational since 2021, is derived from the Russian open-source DroidWatcher surveillance app. It functions as a standalone application and has shown continuous development between January and October 2022. The malware can be controlled via SMS messages and includes sophisticated features like checking for root access and extensive data exfiltration capabilities.

PlainGnome, a more recent addition first discovered in 2024, operates differently as a two-stage deployment malware. The first stage is a minimal installer that drops a malicious APK, while the second stage carries out comprehensive surveillance activities. Unlike BoneSpy, PlainGnome appears to be custom-developed and does not rely on existing open-source code.

The attribution of these malware families to Gamaredon is based on several technical indicators, including:

  • Overlapping command and control (C2) infrastructure

  • Use of dynamic DNS providers

  • Consistent IP address patterns

  • Matching domain naming conventions observed in previous Gamaredon campaigns

Most of the infrastructure associated with these spyware tools is hosted on Russian internet service providers, with many resolving to IP addresses registered to Global Internet Solutions LLC, a company located in Sevastopol, Crimea.

The distribution method for these malware tools remains unclear, but researchers suspect targeted social engineering techniques. The apps have been observed masquerading as legitimate applications like battery monitoring tools, photo galleries, and even trojanized versions of popular messaging apps like Telegram.

While Gamaredon has historically focused on targeting Ukraine, this mobile espionage campaign appears to be expanding the group's reach to other former Soviet states. The discovery underscores the group's evolving capabilities and willingness to develop sophisticated mobile surveillance tools to gather intelligence.

Cybersecurity experts recommend that users in the targeted regions remain vigilant, regularly update their devices, and be cautious about installing applications from unknown sources.

Found this article interesting? Keep visit thesecmaster.com, and our social media page on FacebookLinkedInTwitterTelegramTumblrMedium, and Instagram and subscribe to receive tips like this. 

You may also like these articles: Here are the 5 most contextually relevant blog posts:

Anthony Denis

Anthony Denis a Security News Reporter with a Bachelor's in Business Computer Application. Drawing from a decade of digital media marketing experience and two years of freelance writing, he brings technical expertise to cybersecurity journalism. His background in IT, content creation, and social media management enables him to deliver complex security topics with clarity and insight.

Recently added

Learn More About Cyber Security Security & Technology

“Knowledge Arsenal: Empowering Your Security Journey through Continuous Learning”

Cybersecurity All-in-One For Dummies - 1st Edition

"Cybersecurity All-in-One For Dummies" offers a comprehensive guide to securing personal and business digital assets from cyber threats, with actionable insights from industry experts.

Tools

Featured

View All

Learn Something New with Free Email subscription

Subscribe

Subscribe