LianSpy: new Android spyware targeting Russian users


In March 2024, Kaspersky researchers discovered a campaign targeting individuals in Russia with previously unseen Android spyware they dubbed LianSpy. Kaspersky analysis indicates that the malware has been active since July 2021.

This threat is equipped to capture screencasts, exfiltrate user files, and harvest call logs and app lists. The malicious actor behind LianSpy employs multiple evasive tactics, such as leveraging a Russian cloud service, Yandex Disk, for C2 communications. They also avoid having dedicated infrastructure, and employ a lot of other features to keep the spyware undiscovered. Some of these features suggest that LianSpy is most likely deployed through either an unknown vulnerability or direct physical access to the target phone.

Read more…
Source: Kaspersky


Sign up for our Newsletter


Related:

  • Canada bans Chinese app WeChat from government devices

    October 30, 2023

    Canada has announced it will ban WeChat on government devices. The Chinese-owned app is sometimes referred to as the “everything app” – like WhatsApp, Facebook, Amazon and Tinder all in one. However Western governments have security concerns about it, mainly that the app could be used to spy on users. WeChat is one of the most ...

  • The outstanding stealth of Operation Triangulation

    October 23, 2023

    In the previous blogpost on Triangulation, Kaspersky researchers discussed the details of TriangleDB, the main implant used in this campaign, its C2 protocol and the commands it can receive. The researchers mentioned, among other things, that it is able to execute additional modules. They also mentioned that this operation was quite stealthy. This article details ...

  • Irish-linked spyware used in brazen attacks

    October 21, 2023

    The Irish government is set to investigate a digital surveillance alliance that has been accused of letting its smartphone spyware “run wild across the world”, BBC News NI understands. It comes after Intellexa Limited and its parent company Thalestris were named in a damning report by a leading human rights body. The firms are registered at ...

  • Crambus: New Campaign Targets Middle Eastern Government

    October 19, 2023

    The Iranian Crambus espionage group (aka OilRig, APT34) staged an eight-month-long intrusion against a government in the Middle East between February and September 2023. During the compromise, the attackers stole files and passwords and, in one case, installed a PowerShell backdoor (dubbed PowerExchange) that was used to monitor incoming mails sent from an Exchange Server ...

  • ToddyCat: Keep calm and check logs

    October 12, 2023

    ToddyCat is an advanced APT actor that Kaspersky researchers described in a previous publication last year. The group started its activities in December 2020 and has been responsible for multiple sets of attacks against high-profile entities in Europe and Asia. Kaspersky first publication was focused on their main tools, Ninja Trojan and Samurai Backdoor, and ...

  • Stayin’ Alive – targeted attacks against telecoms and government ministries in Asia

    October 11, 2023

    In the last few months, Check Point Research has been tracking “Stayin’ Alive”, an ongoing campaign that has been active since at least 2021. The campaign operates in Asia, primarily targeting the Telecom industry, as well as government organizations. The “Stayin’ Alive” campaign consists of mostly downloaders and loaders, some of which are used as ...