TF-MAL-apk.residentbat
📛 Threat Title
Malware family: ResidentBat
Description
ThreatFox malware family `apk.residentbat`. Printable name: ResidentBat.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
apk.residentbat
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.residentbat
IOC database
- Type
- domain
- Value
apk.residentbat- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-apk.residentbat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.residentbat
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:www.glasswings.com
ResidentBat : Operational Report & Advisory on KGB spyware in Belarus in 2025 Wed, 24 Dec 2025 15:02:14 +1100 Andrew Pam <xanni [at] glasswings.com.au>
-
web:cyberpress.org
ResidentBat is a sophisticated Android spyware implant used by the Belarusian KGB (State Security Committee) for surveillance operations against journalists and civil society. Discovered by Reporters Without Borders (RSF) and RESIDENT. In December 2025, the NGO reported that the malware provides the KGB with persistent access to the devices of targeted individuals. Once installed via physical ...
-
web:cybersecuritynews.com
A newly documented Android spyware called ResidentBat has been linked to the Belarusian KGB, giving state operators deep and persistent access to the mobile devices of journalists and civil society members. First publicly reported in December 2025 through a joint investigation by Reporters Without Borders (RSF) and RESIDENT.NGO, the malware's code history suggests it was quietly developed as ...
-
web:malpedia.caad.fkie.fraunhofer.de
Details for the ResidentBat malware family including references, samples and yara signatures.
-
web:resident.ngo
Malware Capabilities & Behavior ResidentBat is a modular spyware tool designed to turn a victim's smartphone into a comprehensive surveillance device. It is able to access the following types of data on an infected device: Apps and messengers through screen monitoring capabilities of the included accessibility service.
-
web:rsf.org
As the malware contains the strings "bat" and "resident", we call this spyware ResidentBat . Reporters Without Borders is grateful to Amnesty International's Security Lab for forensic and technical support during this investigation, and for peer-reviewing an earlier draft of this research.
-
web:securityonline.info
Once installed, ResidentBat acts as an all-seeing eye. The malware is bundled as a standard Android app but requests a staggering 38 permissions, granting it access to everything from SMS messages and phone calls to the device's camera and microphone . The core of its power lies in its abuse of Android's Accessibility Service.
-
web:windowsforum.com
The emergence of RESURGE signals more than just another entry in a long line of malware threats. According to CISA, RESURGE contains advanced persistence features inherited from the SPAWNCHIMERA malware family—a group notorious for its ability to survive system reboots and avoid simplistic remediation .
-
web:www.pcrisk.com
What kind of malware is ResidentBat ? ResidentBat is an Android spyware that is installed through physical access to the victim's device. Once infiltrated, it abuses broad application permissions and enables an Accessibility Service, giving it deep and persistent control over the phone. If detected, ResidentBat should be removed immediately.
-
web:www.ukrinform.net
The Digital Security Lab (DSL) of Reporters Without Borders (RSF), together with the Eastern European organization RESIDENT.NGO has identified ResidentBat spyware on the smartphone of a journalist who the Belarusian KGB had previously interrogated. — Ukrinform.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.