Researchers detailed an Android implant known as poprd30.apk that was tied to Fancy Bear / APT28 / Sofacy and disguised as software related to Ukrainian artillery operations. The APK, also referred to as Попр-Д30.apk, was identified as a backdoor that contacted 69.90.132[.]215 and could collect extensive information from infected devices, including SMS messages, call logs, contacts, installed apps, browser history, Wi‑Fi status, mobile data usage, and files stored on the SD card. Although the malware did not request GPS permissions, investigators said it could still infer coarse location through base station and Wi‑Fi data, reinforcing concerns that the app could be used to monitor field units.
A follow-up technical analysis found the sample had been deliberately or accidentally corrupted so it would fail Android parsing checks, and researchers repaired it by removing an extra byte from res/drawable-mdpi/warnings.png, producing a valid signed APK with SHA-256 5b6ea28333399a73475027328812fb42259c12bb24b6650e5def94f4104f385e. The repaired package and related Linux samples showed overlapping tradecraft with X-Agent, including reused RC4 key material, similar command-and-control communication patterns, and encoding and response-check routines that linked the Android implant to broader Sofacy tooling. Analysts noted that such similarities strengthened the connection to X-Agent operations, while stopping short of treating code overlap alone as definitive attribution.

TTPs, infrastructure, and targeting history in one profile.
4 events from the most recent confirmed update back to the earliest known activity.
In its update, CrySyS compared the Android sample's textbook RC4 implementation with related Linux XAgent samples that reused the same key material but used XOR-based routines instead. The update also released a YARA rule named sofacy_xagent to detect Linux Sofacy XAgent variants.
CrySyS reported that the analyzed poprd30.apk sample had been corrupted by an extra byte in res/drawable-mdpi/warnings.png, preventing installation and causing archive errors. After removing the byte, investigators restored a valid signed APK with SHA-256 hash 5b6ea28333399a73475027328812fb42259c12bb24b6650e5def94f4104f385e.
CrySyS analyzed the Android APK poprd30.apk (Попр-Д30.apk) and confirmed it contained backdoor functionality. The report documented communications with 69.90.132[.]215, data theft capabilities, and similarities to X-Agent associated with Fancy Bear/APT28/Sofacy while cautioning that similarity alone did not prove attribution.
CrowdStrike published reporting that linked Fancy Bear to an Android application used to track Ukrainian field artillery units. The references indicate this was a distinct public disclosure in the story, though no event date is explicitly anchored in the provided content.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
4 references tracked. Mallory keeps watching after this page renders.
blog.crysys.hu
Open sourceblog.crysys.hu
Open sourcecrowdstrike.com
Open sourcecrowdstrike.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.