DAAM
Aliases: BouldSpy
- First seen
- 2021-01-01 00:00:00
- Malware type
- botnet, spyware
- Family
- Malware family
- Profile updated
- 2026-07-07 14:05:37
Targeted industries: government-and-public-sector
Targeted regions: country_code:ir
Context
According to PCrisk, DAAM is an Android malware utilized to gain unauthorized access to targeted devices since 2021. With the DAAM Android botnet, threat actors can bind harmful code with a genuine application using its APK binding service. Lookout refers to this malware as BouldSpy and assesses with medium confidence that this Android surveillance tool is used by the Law Enforcement Command of the Islamic Republic of Iran (FARAJA).
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Apk.Daam (report)
- blog.cyble.com — Daam Android Botnet Being Distributed Through Trojanized Applications (report)
- lookout.com — Iranian Spyware Bouldspy (report)