Monokle is a custom Android spyware platform associated with the Russian contractor Special Technology Centre (STC) and has been linked to Russian state surveillance activity. It is designed for covert collection and exfiltration of sensitive data from compromised Android devices, including operation in cases where full root privileges are not available. Documented functionality includes harvesting call history, contact lists, browser history, stored password-related material, user dictionaries and shortcuts, device and network metadata, and capturing photos and videos from the device. Monokle also checks connectivity state such as Wi‑Fi versus mobile data and profiles the handset through hardware and power-related metadata collection. Reported tradecraft includes abuse of Android accessibility services and use of attacker-supplied TLS certificates to support interception and data theft. Monokle has been documented in targeted surveillance cases, including against a Russian programmer whose seized Android device was later found to contain the spyware. The malware is best characterized as targeted mobile surveillance tooling used for espionage and post-compromise monitoring rather than commodity cybercrime.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
В декабре 2024 года Citizen Lab задокументировала установку шпионского ПО Monokle на Android-устройство российского программиста Кирилла Парубца...
3 distinct techniques documented for this family, organized by ATT&CK tactic.
RCSAndroid can collect passwords for Wi-Fi networks and online accounts, including Skype, Facebook, Twitter, Google, WhatsApp, Mail, and LinkedIn. Monokle can retrieve the salt used when storing the user’s password, aiding an adversary in computing the user’s plaintext password/PIN from the stored password hash.
Monokle checks if the device is connected via Wi-Fi or mobile data; Pegasus for Android checks if the device is on Wi-Fi, a cellular network, and is roaming; TianySpy can check to see if Wi‑Fi is enabled; TERRACOTTA can check if the active network connection is metered; TrickMo can collect device network configuration information such as IMSI, IMEI, and Wi‑Fi connection state.
AbstractEmu can collect files from or inspect the device’s filesystem. AhRat can find and exfiltrate files with certain extensions, such as .jpg, .mp4, .html, .docx, and .pdf. BOULDSPY can access browser history and bookmarks, and can list all files and folders on the device.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Spyware installed on an Android device after seizure by the FSB, used for surveillance of a civilian target and attributed through technical artifact analysis by Citizen Lab.
Advanced Android spyware capable of exfiltrating data without root, leveraging accessibility services, performing AiTM attacks, searching for keywords, and recording locked screens to steal credentials. Used in highly targeted attacks.
Software changes: Monokle
Android malware capable of taking photos and videos.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.