Android.Spy.1292.origin is an Android spyware trojan discovered by Doctor Web in 2025. It was used in a targeted espionage campaign against Russian military personnel and was embedded in a trojanized older version of the Alpine Quest mapping application, presented as a free Alpine Quest Pro build. The malware was distributed via a fake Telegram channel impersonating an Alpine Quest software channel, with download links to a Russian Android app catalog, and was later also pushed through the same channel as an application update. Because it is embedded into a working copy of the legitimate app, the trojanized application appears to function normally while covertly collecting data.
On launch, the malware collects and sends to a command-and-control server the victim’s mobile phone number, account information, phonebook contacts, current date, geolocation, information about files stored on the device, and the application version. Some stolen data is also relayed to an attacker-controlled Telegram bot, including geolocation updates whenever the device location changes. After receiving file inventory data, the operators can command the malware to download and execute additional modules, expanding functionality and enabling theft of selected files from the device. Doctor Web reported particular operator interest in confidential documents sent via Telegram and WhatsApp, as well as Alpine Quest’s locLog location log file. High-confidence capabilities therefore include location monitoring, confidential data exfiltration, file inventory collection, modular payload delivery, and targeted file theft from infected Android devices.
The campaign is described as targeting Russian military users, likely because Alpine Quest is used in military contexts. No confirmed attribution to a specific threat actor is provided in the content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
“Each time it is launched, the trojan collects and sends the following data to the C&C server…”
“…distribute it in various ways, including through one of the Russian Android app catalogs… provided a link for downloading the app in one of the Russian app catalogs.” | “…can download additional modules… threat actors can command the trojan to download and run additional modules…”
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android spyware trojan embedded in a trojanized Alpine Quest app; exfiltrates device/account identifiers, contacts, geolocation, and files, and can steal specific files on command (including documents shared via messengers and Alpine Quest location logs).
Trojanized Alpine Quest build used for espionage; collects device and personal data (phone numbers/accounts, contacts, geolocation, file inventory) and can exfiltrate selected files on command, including messenger-delivered documents and Alpine Quest location logs.
Trojanized Alpine Quest build used for espionage: collects device and sensitive data (e.g., contacts, geolocation, file info) and can exfiltrate selected files on command; interest included confidential documents sent via messengers and Alpine Quest location logs.
Spyware trojan embedded in a modified Alpine Quest app and distributed via a fake Telegram channel/app catalog; exfiltrates phone/account data, contacts, geolocation, and files; can steal specific files on command (including messaging-app documents and Alpine Quest location logs).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.