Android.Backdoor.916.origin is a multifunctional Android backdoor first observed by Doctor Web in January 2025 and reported publicly in August 2025. It was described as spreading in the wild but being used primarily in targeted attacks against representatives and employees of Russian companies and businesses. Distribution was reported via direct messages in popular messaging apps, where the malware was delivered as an APK masquerading as a fake antivirus application, including under the name "GuardCB," with Russian-language interface elements and branding resembling Russian state or law-enforcement institutions; additional observed variants included names such as "SECURITY_FSB" and "ФСБ".
According to the reporting, once installed the malware requests extensive permissions, including access to geolocation, microphone, camera, SMS, contacts, call history, media files, background execution, device administrator rights, and Accessibility Service. It maintains persistence by launching multiple services, checking them every minute, and restarting them if needed. It communicates with command-and-control infrastructure and can store configuration for multiple C2 servers, with support for switching across hosting providers.
Documented capabilities include theft of confidential data and user surveillance. Doctor Web reported that the backdoor can upload incoming and outgoing SMS, contacts, call history, geolocation data, images from storage, and device network/interface information to its C2. It can start and stop audio streaming from the microphone, video streaming from the camera, and screen streaming from the device. It also supports execution of received shell commands and can enable or disable self-protection.
The malware abuses Android Accessibility Service for keylogging and for intercepting content from applications including Telegram, WhatsApp, Gmail, Google Chrome, Yandex Start, and Yandex Browser. Reporting also states it can use Accessibility Service to resist deletion when commanded by the operators. Doctor Web assessed the malware as an espionage-oriented Android backdoor rather than a mass-market commodity threat.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
Once installed, the backdoor requests a list of permissions, from geolocation and audio recording to camera access and SMS data. It also demands device administrator rights and access to Android’s Accessibility Service, which lets it act like a keylogger and intercept content from popular apps.
Once installed, the backdoor requests a list of permissions, from geolocation and audio recording to camera access and SMS data. It also demands device administrator rights and access to Android’s Accessibility Service, which lets it act like a keylogger and intercept content from popular apps.
The fake app uses a disguise to trick victims. Its icon resembles the emblem of the Russian Central Bank placed on a shield, making it look trustworthy. Once installed, it runs what looks like an antivirus scan, complete with fake detection results that are randomly generated to appear convincing.
It also demands device administrator rights and access to Android’s Accessibility Service, which lets it act like a keylogger... The malware also takes advantage of Android’s Accessibility Service as a way to protect itself. This feature is abused not only to steal keystrokes...
It can livestream audio from a microphone, broadcast video from the camera, steal text as users type it, and upload contacts, SMS, images, and call history.
It also demands device administrator rights and access to Android’s Accessibility Service, which lets it act like a keylogger... The malware also takes advantage of Android’s Accessibility Service as a way to protect itself. This feature is abused not only to steal keystrokes...
Additionally, it even has the ability to stream a device’s screen in real time.
This feature is abused not only to steal keystrokes but also to block attempts to remove the malware if attackers issue such a command. That self-protection capability means even if victims realize their device is compromised, removal can be difficult without dedicated security software.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Targeted Android backdoor masquerading as an antivirus APK delivered via messenger DMs; supports surveillance (mic/camera), geolocation tracking, messenger/browser data theft, and keylogging.
Mobile backdoor/spyware distributed via messenger DMs masquerading as antivirus; enables remote spying and theft of confidential data; primarily targets employees of Russian companies.
Mobile backdoor disguised as antivirus and delivered via direct messages in messengers; collects confidential data and enables spying on victims.
Targeted Android backdoor masquerading as an antivirus APK delivered via messenger DMs; supports surveillance (mic/camera), geolocation tracking, messenger/browser data theft, and keylogging (including passwords).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.