TF-MAL-apk.bone_spy
📛 Threat Title
Malware family: BoneSpy
Description
ThreatFox malware family `apk.bone_spy`. Printable name: BoneSpy.
Indicators of Compromise (0)
No indicators of compromise on this threat.
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:cybersecuritynews.com
Two sophisticated Linux rootkits are posing increasingly serious threats to network security by exploiting eBPF technology to hide their presence from traditional detection systems. BPFDoor and Symbiote, both originating from 2021, represent a dangerous class of malware that combines advanced kernel-level access with powerful evasion capabilities.
-
web:github.com
This repository provides a publicly available dataset of Linux system call traces collected using eBPF for malware detection research. The dataset includes system call activity traces from 467 infected samples and clean environments, captured under both idle and user-activity-simulated scenarios.
-
web:malpedia.caad.fkie.fraunhofer.de
According to Lookout, BoneSpy is based on the Russian-developed, open-source DroidWatcher surveillanceware, featuring nearly identical code, names, and log messages in multiple classes related to the handling of databases containing collected exfil data such as call logs, location tracking, SMS messages, notifications, and browser bookmarks. Class names for many entry points (receivers ...
-
web:thehackernews.com
The Russia-linked state-sponsored threat actor tracked as Gamaredon has been attributed to two new Android spyware tools called BoneSpy and PlainGnome, marking the first time the adversary has been discovered using mobile-only malware families in its attack campaigns. " BoneSpy and PlainGnome target ...
-
web:threatintelligence.garden.handsomezebra.com
BoneSpy Description (Lookout) The BoneSpy family showed evidence of continuous development between roughly January and October 2022, after which samples began using consistent lure theming and code structure.
-
web:www.bugsfighter.com
How BoneSpy Spyware infected your device BoneSpy Spyware infiltrates Android devices through various deceptive methods, primarily capitalizing on trojanized applications and phishing tactics. This malware often masquerades as legitimate apps, such as battery monitors, gallery apps, or even enterprise tools like Samsung Knox Manage, making it difficult for users to identify the threat. It ...
-
web:www.cisa.gov
It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.
-
web:www.itfunk.org
BoneSpy is a sophisticated Android spyware program that has been active since at least 2021. Rooted in the Russian open-source surveillance software DroidWatcher, BoneSpy has been linked to the Russian cyber threat group Gamaredon, also known as Primitive Bear or Shuckworm.
-
web:www.pcrisk.com
What kind of malware is BoneSpy ? BoneSpy is an Android-targeting spyware that has been around since at least 2021. This malicious program has its basis from the Russian open-source surveillance software DroidWatcher. BoneSpy is associated with a Russian threat actor dubbed Gamaredon (aka Primitive Bear and Shuckworm).
-
web:www.rivitmedia.com
What Is BoneSpy Malware ? BoneSpy is classified as spyware, a malicious program designed to collect and exfiltrate sensitive data from infected Android devices. Over time, multiple variants of BoneSpy have been identified, with different capabilities and functionalities.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.