Belarusian authorities have been found to deploy a previously unknown spyware, dubbed ResidentBat, on the smartphones of local journalists during police interrogations. The spyware was discovered after a journalist, interrogated by the Belarusian KGB, received malware alerts on their device. Investigations by Reporters Without Borders (RSF) and RESIDENT.NGO revealed that the spyware can access call logs, SMS and encrypted app messages, record audio, capture screens, and exfiltrate local files. The infection process reportedly involved authorities observing the journalist unlock their phone, then installing the spyware while the device was out of the journalist's possession. ResidentBat's server infrastructure has been active since at least March 2021, coinciding with anti-government protests in Belarus.
The use of ResidentBat highlights a broader trend of authoritarian regimes leveraging spyware to target journalists and suppress independent reporting. Similar tactics have been observed in countries such as Serbia and Kenya, where authorities install surveillance tools on detainees' devices during questioning. The discovery of ResidentBat underscores the ongoing risks faced by journalists in Belarus, where state surveillance is used as a tool of repression. Google has been notified and is expected to alert other users potentially affected by this spyware.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
After confirming the spyware, RSF notified Google about the ResidentBat case. Google said it planned to alert affected users about the compromise.
The infection was discovered after antivirus software flagged suspicious components on the journalist's phone, prompting forensic analysis by Reporters Without Borders and RESIDENT.NGO. Their investigation identified the malware as a previously unknown spyware family dubbed ResidentBat and documented its surveillance capabilities.
A Belarusian journalist's Android phone was infected with ResidentBat after the journalist was detained and interrogated by the Belarusian KGB. The case fit a broader pattern in which authorities allegedly install spyware on journalists' devices while they are in custody.
Forensic analysis by Reporters Without Borders indicated the previously unknown Android spyware later named ResidentBat had been in use since at least 2021. The malware was designed to extract call logs, SMS, encrypted app messages, files, microphone recordings, and screen captures from compromised devices.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcenews.risky.biz
Open sourcetherecord.media
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.