PlainGnome

First seen
2024-01-01 00:00:00
Malware type
spyware, dropper
Family
Malware family
Last IoC activity
2026-04-17 06:52:02
Profile updated
2026-07-07 14:04:35

Targeted industries: technology-and-telecommunications

Context

According to Lookout, PlainGnome consists of a two-stage deployment in which a very minimal first stage drops a malicious APK once it’s installed. The code of PlainGnome’s second stage payload evolved significantly from January 2024 through at least October. In particular, PlainGnome’s developers shifted to using Jetpack WorkManager classes to handle data exfiltration, which eases development and maintenance of related code. In addition, WorkManager allows for specifying execution conditions. For example, PlainGnome only exfiltrates data from victim devices when the device enters an idle state. This mechanism is probably intended to reduce the chance of a victim noticing the presence of PlainGnome on their device. As opposed to the minimalist first (installer) stage, the second stage carries out all surveillance functionality and relies on 38 permissions.

Reports & references

  • lookout.com — Gamaredon Russian Android Surveillanceware (report)
  • malpedia.caad.fkie.fraunhofer.de — Apk.Plain Gnome (report)

External references