BoneSpy

First seen
2021-06-15 00:00:00
Malware type
spyware
Last IoC activity
2026-06-04 15:56:23
Profile updated
2026-07-07 14:04:33

Targeted industries: government-and-public-sector technology-and-telecommunications

Context

According to Lookout, BoneSpy is based on the Russian-developed, open-source DroidWatcher surveillanceware, featuring nearly identical code, names, and log messages in multiple classes related to the handling of databases containing collected exfil data such as call logs, location tracking, SMS messages, notifications, and browser bookmarks. Class names for many entry points (receivers, activities, and services) were either the same or very similar to DroidWatcher samples.

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Apk.Bone Spy (report)
  • lookout.com — Gamaredon Russian Android Surveillanceware (report)

External references