s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-apk.residentbat

📛 Threat Title

Malware family: ResidentBat

Category: ResidentBat First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `apk.residentbat`. Printable name: ResidentBat.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain apk.residentbat VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.residentbat

IOC database

Type
domain
Value
apk.residentbat
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-apk.residentbat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.residentbat

References (1)

Remediations (10)

  • web:www.glasswings.com

    ResidentBat : Operational Report & Advisory on KGB spyware in Belarus in 2025 Wed, 24 Dec 2025 15:02:14 +1100 Andrew Pam <xanni [at] glasswings.com.au>

  • web:cyberpress.org

    ResidentBat is a sophisticated Android spyware implant used by the Belarusian KGB (State Security Committee) for surveillance operations against journalists and civil society. Discovered by Reporters Without Borders (RSF) and RESIDENT. In December 2025, the NGO reported that the malware provides the KGB with persistent access to the devices of targeted individuals. Once installed via physical ...

  • web:cybersecuritynews.com

    A newly documented Android spyware called ResidentBat has been linked to the Belarusian KGB, giving state operators deep and persistent access to the mobile devices of journalists and civil society members. First publicly reported in December 2025 through a joint investigation by Reporters Without Borders (RSF) and RESIDENT.NGO, the malware's code history suggests it was quietly developed as ...

  • web:malpedia.caad.fkie.fraunhofer.de

    Details for the ResidentBat malware family including references, samples and yara signatures.

  • web:resident.ngo

    Malware Capabilities & Behavior ResidentBat is a modular spyware tool designed to turn a victim's smartphone into a comprehensive surveillance device. It is able to access the following types of data on an infected device: Apps and messengers through screen monitoring capabilities of the included accessibility service.

  • web:rsf.org

    As the malware contains the strings "bat" and "resident", we call this spyware ResidentBat . Reporters Without Borders is grateful to Amnesty International's Security Lab for forensic and technical support during this investigation, and for peer-reviewing an earlier draft of this research.

  • web:securityonline.info

    Once installed, ResidentBat acts as an all-seeing eye. The malware is bundled as a standard Android app but requests a staggering 38 permissions, granting it access to everything from SMS messages and phone calls to the device's camera and microphone . The core of its power lies in its abuse of Android's Accessibility Service.

  • web:windowsforum.com

    The emergence of RESURGE signals more than just another entry in a long line of malware threats. According to CISA, RESURGE contains advanced persistence features inherited from the SPAWNCHIMERA malware family—a group notorious for its ability to survive system reboots and avoid simplistic remediation .

  • web:www.pcrisk.com

    What kind of malware is ResidentBat ? ResidentBat is an Android spyware that is installed through physical access to the victim's device. Once infiltrated, it abuses broad application permissions and enables an Accessibility Service, giving it deep and persistent control over the phone. If detected, ResidentBat should be removed immediately.

  • web:www.ukrinform.net

    The Digital Security Lab (DSL) of Reporters Without Borders (RSF), together with the Eastern European organization RESIDENT.NGO has identified ResidentBat spyware on the smartphone of a journalist who the Belarusian KGB had previously interrogated. — Ukrinform.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.