Citizen Lab and The First Department reported that Russian programmer Kirill Parubets received his Android phone back from authorities with spyware covertly installed after his detention in 2024. The malicious app was disguised as a trojanized version of Cube Call Recorder and, according to investigators, enabled extensive surveillance including location tracking, call recording, keylogging, screen capture, file theft, password extraction, access to messages in other apps, JavaScript injection, shell command execution, and recovery of the device unlock password.
Researchers said the malware is closely related to the Monokle Android spyware family previously documented by Lookout and linked to Special Technology Center, Ltd., a Russian government contractor, though the sample also showed differences that may indicate an updated variant or a new strain reusing Monokle code. The report also said Parubets was beaten, pressured to disclose his device password, and threatened by the FSB with severe punishment to coerce him into becoming an informant, underscoring the risk of using devices after they have been seized and returned by hostile state authorities.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
In June 2024, Russian authorities detained Russian programmer Kirill Parubets for 15 days after accusing him of sending money to Ukraine. During a search of his apartment, authorities confiscated his Android phone, and Parubets said he was beaten and pressured to reveal its password while the FSB tried to recruit him as an informant.
In 2019, Lookout previously reported on the Monokle spyware family and linked it to Special Technology Center, Ltd., a Russian government contractor based in St. Petersburg. Citizen Lab later cited this prior reporting as the baseline for comparing the Parubets sample.
The First Department identified a likely malicious app on Parubets' phone, and Citizen Lab confirmed it was a trojanized version of Cube Call Recorder. The malware had extensive surveillance capabilities, and researchers assessed it was closely related to Monokle, either as an updated variant or new malware reusing much of the same code.
After his release, Parubets received his phone back at the FSB headquarters in Lubyanka and noticed unusual behavior, including a suspicious notification reading "Arm cortex vx3 synchronization." This prompted scrutiny of the device after it had been out of his control in Russian custody.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.