Researchers analyzed an Android spyware APK named Process Manager (package com.remote.app) that masquerades as a system component, requests extensive permissions, hides its icon after launch, and persists in the background using device administration features. The malware collects a wide range of information from infected phones, including contacts, call logs, SMS messages, files, clipboard contents, Wi-Fi details, notification content, GPS location, and audio recordings, then packages the data in JSON and sends it to a command-and-control server at 82.146.35[.]240.
The spyware also supports command-based tasking to activate specific collection modules and can download additional payloads from attacker-controlled links. In one observed case, it attempted to install the Play Store app Roz Dhan: Earn Wallet cash, apparently to abuse the app’s referral program for profit. Although the C2 infrastructure overlaps with servers previously associated with Turla and Penquin-related activity, researchers said the malware’s relatively low sophistication and monetization behavior do not support attributing the operation to Turla.

Pull IOCs and campaign context straight into your stack.
5 events from the most recent confirmed update back to the earliest known activity.
The BleepingComputer article was updated to clarify that the reported connection to Turla relied on weak evidence rather than firm attribution.
Lab52 observed the malware downloading the Google Play app "Roz Dhan: Earn Wallet cash," apparently to abuse its referral system and generate commissions for the operators.
Despite the infrastructure overlap, the researchers concluded attribution of the Android spyware to Turla was not possible based on the malware's capabilities and low sophistication, suggesting shared infrastructure instead.
During the analysis, Lab52 found the spyware communicated with 82.146.35[.]240, infrastructure previously associated with Penquin-related activity and other servers used in Turla-linked operations.
Lab52 discovered a malicious Android APK named "Process Manager" on VirusTotal and analyzed it as spyware that disguises itself as a system component, requests extensive permissions, hides its icon, and exfiltrates data to 82.146.35[.]240.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 9 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.