Tag: Android Spyware

Samsung Mobile Flaw Exploited as Zero-Day to Deploy LANDFALL Android Spyware
News

Samsung Mobile Flaw Exploited as Zero-Day to Deploy LANDFALL Android Spyware

In targeted assaults within the Middle East, a security vulnerability in Samsung Galaxy Android devices that has now been fixed was exploited as a zero-day to deploy LANDFALL, an "commercial-grade" Android spyware. Palo Alto Networks Unit 42 reported that the activity involved taking advantage of CVE-2025-21042 (CVSS score: 8.8), which is an out-of-bounds write vulnerability in the "libimagecodec.quram.so" component that could permit remote attackers to run arbitrary code. In April 2025, Samsung dealt with the issue. According to Unit 42, this vulnerability was actively exploited in the wild before Samsung implemented a patch for it in April 2025, after reports of real-world attacks. Based on VirusTotal submission data, potential targets of the activity tracked read more about Samsu...
Beware of Android Spyware Disguised as Signal Encryption Plugin and ToTok Pro
News

Beware of Android Spyware Disguised as Signal Encryption Plugin and ToTok Pro

Researchers studying cybersecurity have found two Android spyware operations called ProSpy and ToSpy that target users in the United Arab Emirates (U.A.E.) by mimicking apps like Signal and ToTok. According to Slovak cybersecurity firm ESET, the malicious apps are disseminated through social engineering and phony websites to fool unwary users into downloading them. Once installed, both strains of spyware software gain ongoing access to Android devices that have been infected and begin to steal data. According to ESET researcher Lukáš Štefanko, none of the spyware-containing apps could be found in official app stores and had to be manually installed via unaffiliated websites masquerading as trustworthy services. Interestingly, one of the websites that spread the ToSpy malware family ...
Gamaredon Deploys Android Spyware “BoneSpy” and “PlainGnome” in Former Soviet States
News

Gamaredon Deploys Android Spyware “BoneSpy” and “PlainGnome” in Former Soviet States

Two new Android spyware tools, BoneSpy and PlainGnome, have been linked to the Russia-affiliated state-sponsored threat actor known as Gamaredon. This is the first time the adversary has been seen utilizing malware families exclusive to mobile devices in its assault activities. According to an investigation by Lookout, BoneSpy and PlainGnome target former Soviet states and concentrate on victims who speak Russian. Data including SMS messages, call logs, audio recordings, device location, camera images, and contact lists are all gathered by BoneSpy and PlainGnome. Gamaredon, a hacker collective associated with Russia's Federal Security Service (FSB), is also known by the names Aqua Blizzard, Armageddon, BlueAlpha, Hive0051, Iron Tilden, Primitive Bear, Shuckworm, Trident Ursa, UAC-00...
New EagleMsgSpy Android spyware used by Chinese police, researchers say
News

New EagleMsgSpy Android spyware used by Chinese police, researchers say

The 'EagleMsgSpy' Android malware, which was previously unknown, has been found and is thought to be utilized by Chinese government enforcement to snoop on mobile devices. The spyware was created by Wuhan Chinasoft Token Information Technology Co., Ltd. and has been in use since at least 2017, according to a recent Lookout investigation. Lookout provides a wealth of evidence that connects EagleMsgSpy to its creators and operators, such as domain names, IP addresses connected to C2 servers, explicit mentions in internal documents, and public contracts. Additionally, the researchers discovered hints that an iOS variant might exist read more about New EagleMsgSpy Android spyware used by Chinese police, researchers say. Get up to date on the latest cybersecurity news and enhance y...
Android spyware ‘Mandrake’ hidden in apps on Google Play since 2022
News

Android spyware ‘Mandrake’ hidden in apps on Google Play since 2022

Google Play, the official app store for the platform, has revealed that five programs that have been downloaded 32,000 times include a new version of the Android malware known as "Mandrake." In 2020, Bitdefender released the first report on Mandrake. The experts noted that the virus has been active in the field since at least 2016 and highlighted its advanced espionage capabilities. Kaspersky has recently shown that five apps uploaded to Google Play in 2022 allowed a new Mandrake version with improved obfuscation and evasion to infiltrate the store. The last app, AirFS, which was the most successful in terms of popularity and infections, was deleted at the end of March 2024 read more about Android spyware 'Mandrake' hidden in apps on Google Play since 2022. Get up to date on t...
Researchers Link DragonEgg Android Spyware to LightSpy iOS Surveillanceware
News

Researchers Link DragonEgg Android Spyware to LightSpy iOS Surveillanceware

Recent research has shown connections between the advanced modular iOS espionage program LightSpy and the Android spyware DragonEgg. In July 2023, Lookout initially identified DragonEgg and WyrmSpy (also known as AndroidControl) as malware strains that may collect private information from Android devices. It was credited to the nation-state organization APT41 from China. Contrarily, information regarding LightSpy was revealed in March 2020 as a result of a campaign known as Operation Poisoned News, in which Apple iPhone owners in Hong Kong were singled out for watering hole assaults to install the spyware read more Researchers Link DragonEgg Android Spyware to LightSpy iOS Surveillanceware. Stay informed with the best cybersecurity news and raise your cybersecurity awareness with...
European Bank Customers Targeted in SpyNote Android Trojan Campaign
News

European Bank Customers Targeted in SpyNote Android Trojan Campaign

An intensive operation discovered in June and July 2023 targets a variety of European consumers of several banks using the Android banking trojan known as SpyNote. Italian cybersecurity company Cleafy stated in a technical report published on Monday that "the spyware is distributed through email phishing or smishing campaigns and the fraudulent activities are executed with a combination of remote access trojan (RAT) capabilities and vishing attack." Like previous Android banking Trojans, SpyNote, also known as SpyMax, uses Android's accessibility permissions in order to obtain other crucial permissions and harvest private information from compromised devices. The malware strain is noteworthy since it performs both financial fraud and spyware simultaneously read more European Bank Cu...
BouldSpy Android Spyware: Iranian Government’s Alleged Tool for Spying on Minority Groups
News

BouldSpy Android Spyware: Iranian Government’s Alleged Tool for Spying on Minority Groups

Over 300 members of minority groups have been spied on using a new Android surveillance app that the Iranian government may use. The Law Enforcement Command of the Islamic Republic of Iran (FARAJA) has been tentatively linked to the virus, known as BouldSpy. Iranian Kurds, Baluchis, Azeris, and Armenian Christian organizations are among the groups targeted. Based on data that was exfiltrated and featured images of drugs, weapons, and official FARAJA documents, Lookout speculated that the spyware may have been used to combat and monitor illegal trading in all three areas read more BouldSpy Android Spyware Iranian Government's Alleged Tool for Spying on Minority Groups. With ReconBee.com Stay ahead of the latest threats with in-depth coverage of cyber attacks and cybersecurity tren...