ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
SUBSCRIBE
ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
ZeroSecurity - Information Security News
No Result
View All Result
Home Malware

LianSpy: New Android Spyware Targeting Russian Users

Kyle by Kyle
August 7, 2024
in Malware, Mobile Security
Reading Time: 2 mins read
Photo of LianSpy Android Spyware targeting Russia
Share on FacebookShare on Twitter

Cybersecurity researchers at Kaspersky have uncovered a previously unknown Android spyware called LianSpy. This sophisticated malware has been actively targeting Russian users since July 2021. LianSpy’s primary functions include capturing screencasts, exfiltrating user files, and harvesting call logs and app lists.

Evasion Techniques

LianSpy employs various evasion techniques to avoid detection:

  • Using Yandex Disk, a Russian cloud service, for command and control (C2) communications
  • Avoiding dedicated infrastructure to remain undetected
  • Disguising itself as a legitimate app like Alipay or system services
  • Bypassing Android 12’s privacy indicators by modifying settings
  • Hiding notifications from background services
  • Suppressing status bar notifications with specific phrases

Deployment and Initialization

The exact deployment method for LianSpy remains unclear, but researchers suspect it involves either an unknown vulnerability or direct physical access to the victim’s device. Upon installation, the spyware:

You might also like

How Hackers Still Manage to Compromise MFA

Chinese Hackers Hijack Notepad++ Updates in 6-Month Supply Chain Campaign

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

  1. Checks for system app status to obtain necessary permissions automatically
  2. Requests permissions for screen overlay, notifications, background activity, contacts, and call logs if not a system app
  3. Verifies it’s not being executed in a controlled environment
  4. Sets up its configuration with predefined values
  5. Stores configuration in SharedPreferences for persistence across reboots

Operational Mechanisms

Once activated, LianSpy:

  • Hides its icon
  • Registers a built-in broadcast receiver to receive system intents
  • Triggers various malicious activities, including screen capturing and data exfiltration
  • Updates its configuration by searching for specific files on the threat actor’s Yandex Disk every 30 seconds

Data Collection and Encryption

LianSpy stores collected data in an SQL table called Con001, which includes the data type and its SHA-256 hash. The encryption process involves:

  1. Generating an AES key using a secure pseudorandom number generator
  2. Encrypting the AES key with a hardcoded public RSA key

This approach ensures that only someone with the corresponding private RSA key can decrypt the stolen data.

Advanced Evasion and Exfiltration

LianSpy demonstrates advanced capabilities for evading detection and exfiltrating data:

  • Capturing screenshots stealthily using the screencap command with root access
  • Utilizing cloud and Pastebin services to obscure malicious activity
  • Encrypting exfiltrated data to prevent victim identification
  • Gaining root access through a modified su binary

Command and Control Infrastructure

Instead of using its infrastructure, LianSpy relies on Yandex Disk for data exfiltration and storing configuration commands. The communication with its C2 server is unidirectional, with the malware handling update checks and data exfiltration independently. Yandex Disk credentials can be updated via a hardcoded Pastebin URL, which may vary among malware variants.

Previous Post

APT41 Targets Taiwanese Government Research Institute with ShadowPad and Cobalt Strike

Next Post

Microsoft Discloses High-Severity Zero-Day Vulnerability (CVE-2024-38200) in Office 2016 and Later Versions

Kyle

Kyle

Writer, and editor at ZeroSecurity. Interested in Information Security, the Blockchain, and an overall tech enthusiast. "Formal education will make you a living; self-education will make you a fortune." Contact me here: [email protected]

Recommended For You

How Hackers Still Manage to Compromise MFA

How Hackers Still Manage to Compromise MFA

March 6, 2026
Chinese Hackers Hijack Notepad++ Updates in 6-Month Supply Chain Campaign

Chinese Hackers Hijack Notepad++ Updates in 6-Month Supply Chain Campaign

February 6, 2026

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

January 30, 2026

DoubleClickjacking – The Stealthy New Web Exploit Threatening User Security

January 1, 2025

BadBox Botnet Infects Over 190,000 Android Devices Worldwide

December 20, 2024

FBI Warns of HiatusRAT Targeting Network Devices Worldwide

December 18, 2024

Related News

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

January 30, 2026
KPMG Netherlands Listed as Victim by Nova Ransomware Group

KPMG Netherlands Listed as Victim by Nova Ransomware Group

January 24, 2026
RansomHouse Claims Breach of Key Apple Assembler Luxshare

RansomHouse Claims Breach of Key Apple Assembler Luxshare

January 20, 2026
ZeroSecurity - Information Security News

We cover the latest in technology news, Crypto, Artificial Intelligence, and the threat trends impacting these sectors.

Categories

Piracy

Tutorials

Programming

Malware Analysis

Downloads

  • Contact us
  • Press
  • Writers
  • Privacy Policy
  • Terms of Service

© 2026 ZeroSecurity, All Rights Reserved.

No Result
View All Result
  • Home
  • Security
    • Tools
  • Exploits
  • Data Breaches
  • Malware
  • Privacy
  • Mobile Security
  • Contact Us
    • Press
  • Privacy Policy

© 2026 ZeroSecurity, All Rights Reserved.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.