A targeted Android spyware implant dubbed ResidentBat has been linked to Belarusian state surveillance operations, with reporting tying it to the Belarusian KGB and victimology focused on journalists and civil society. The implant is assessed to have been under development since at least 2021 and was publicly exposed in December 2025 via a joint investigation by Reporters Without Borders (RSF) and RESIDENT.NGO. Unlike mass-distributed mobile malware, ResidentBat is deployed through hands-on access: operators use Android Debug Bridge (ADB) to sideload an APK, manually grant permissions, and disable Google Play Protect, trading scale for high-confidence, deliberate targeting.
Post-compromise, ResidentBat supports broad device surveillance and data theft, including access to SMS and call logs, microphone audio recording, screenshots, and local files, and it is reported to be able to intercept traffic from encrypted messaging apps. Infrastructure analysis attributed to Censys described a consistent C2 fingerprint, including self-signed TLS certificates with the common name CN=server and control traffic over a narrow port range 7000–7257; observed hosting was concentrated in Europe and Russia (including the Netherlands, Germany, Switzerland, and Russia). The C2 is described as supporting data collection, operator tasking, and configuration updates to maintain persistent control over infected devices.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
On February 26, 2026, reporting summarized ResidentBat's functionality, including collection of SMS and call logs, microphone recording, screenshots, file access, encrypted messaging traffic interception, and remote device wiping. The same reporting described its hands-on deployment via ADB sideloading, manual permission grants, and disabling of Google Play Protect.
By February 2026, analysts reported active ResidentBat command-and-control infrastructure across ten hosts concentrated in the Netherlands, Germany, Switzerland, and Russia. Researchers also characterized technical traits including self-signed TLS certificates, a narrow port range, and anti-forensics behavior on the servers.
In December 2025, Reporters Without Borders and RESIDENT.NGO first publicly disclosed the ResidentBat Android spyware operation. Their investigation linked the spyware to highly targeted device compromise requiring physical access for installation.
Code history for the ResidentBat Android spyware indicates the operation's development dates back to 2021. The malware was later assessed as part of a Belarusian KGB-linked espionage effort targeting journalists and civil society members.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcethehackernews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.