DAAM

Aliases: BouldSpy

First seen
2021-01-01 00:00:00
Malware type
botnet, spyware
Family
Malware family
Profile updated
2026-07-07 14:05:37

Targeted industries: government-and-public-sector

Targeted regions: country_code:ir

Context

According to PCrisk, DAAM is an Android malware utilized to gain unauthorized access to targeted devices since 2021. With the DAAM Android botnet, threat actors can bind harmful code with a genuine application using its APK binding service. Lookout refers to this malware as BouldSpy and assesses with medium confidence that this Android surveillance tool is used by the Law Enforcement Command of the Islamic Republic of Iran (FARAJA).

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Apk.Daam (report)
  • blog.cyble.com — Daam Android Botnet Being Distributed Through Trojanized Applications (report)
  • lookout.com — Iranian Spyware Bouldspy (report)

External references