CISA and the UK National Cyber Security Centre published a joint malware analysis report on Infamous Chisel, an Android-focused malware family attributed to Russia’s military intelligence unit GRU 85th Main Special Service Center (GTsSS), Unit 26165. The malware was identified on Android tablets used by the Ukrainian military and is described as a collection of components that provide persistent access, periodic device scanning, file exfiltration, and traffic tunneling from compromised devices. The agencies said the capability appears designed primarily for espionage, enabling operators to harvest sensitive military information from infected devices.
The report says Infamous Chisel can search directories and file types of operational interest, monitor network information, and use modules based on tools such as Tor and SOCKS to route traffic through infected Android devices. Analysts noted the malware was likely deployed through physical access or other compromise methods rather than broad app-store distribution, and assessed some code as poorly obfuscated and narrowly tailored to the operational environment. The publication provides technical indicators and defensive guidance to help organizations detect the malware, investigate Android device compromise, and reduce exposure to mobile espionage activity.

TTPs, infrastructure, and targeting history in one profile.
1 event from the most recent confirmed update back to the earliest known activity.
CISA and the UK National Cyber Security Centre released a joint malware analysis report on Infamous Chisel, detailing the malware's capabilities and technical characteristics. The publication disclosed technical findings intended to support detection and analysis of the malware.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.