BoneSpy
- First seen
- 2021-06-15 00:00:00
- Malware type
- spyware
- Last IoC activity
- 2026-06-04 15:56:23
- Profile updated
- 2026-07-07 14:04:33
Targeted industries: government-and-public-sector technology-and-telecommunications
Context
According to Lookout, BoneSpy is based on the Russian-developed, open-source DroidWatcher surveillanceware, featuring nearly identical code, names, and log messages in multiple classes related to the handling of databases containing collected exfil data such as call logs, location tracking, SMS messages, notifications, and browser bookmarks. Class names for many entry points (receivers, activities, and services) were either the same or very similar to DroidWatcher samples.
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Apk.Bone Spy (report)
- lookout.com — Gamaredon Russian Android Surveillanceware (report)