New Android Malware Targets Russian Business Executives

27 Aug 2025

A newly discovered Android malware, tracked as Android.Backdoor.916.origin, is making headlines for masquerading as a legitimate antivirus tool allegedly developed by Russia's Federal Security Service (FSB). While its presence in the digital realm raises concerns, it's not linked to any known malware families, suggesting a novel creation.

According to findings from Russian mobile security firm Dr. Web, this malware specifically targets the executives of Russian businesses. It displays sophisticated spying capabilities, allowing it to snoop on conversations, stream video from the phone camera, record audio, log keystrokes, and exfiltrate communication data from popular messenger apps.

Targeted Approach and Distribution

Since its first detection in January 2025, Android.Backdoor.916.origin has surfaced in multiple versions, pointing to ongoing development efforts. Distribution tactics, infection methods, and the use of a Russian-only interface strongly suggest that this malware is designed solely for Russian users. Two primary brandings have been observed: "GuardCB," impersonating the Central Bank of the Russian Federation, and "SECURITY_FSB" or "ФСБ," impersonating the FSB.

The fake antivirus app simulates virus scans and generates false positive detections about 30% of the time, effectively discouraging users from removing it. Upon installation, it requests a slew of high-risk permissions, such as access to geolocation, SMS, media, camera, and audio, as well as more severe permissions like device-admin rights and the ability to alter the lock screen.

Dangerous Capabilities

This Android malware links to command-and-control servers, which can then instruct it to perform a variety of unsavory tasks: exfiltrating SMS, contacts, call histories, and location data; activating microphones, cameras, and screen streaming; capturing text input, messenger, or browser content from apps like Telegram, WhatsApp, Gmail, Chrome, and Yandex; executing shell commands; and ensuring its own persistence and self-protection.

Moreover, Dr. Web's research reveals that the malware demonstrates resilience, with a contingency capability to switch hosting providers as needed.

To aid in the combat against Android.Backdoor.916.origin, Dr. Web has published a comprehensive list of indicators of compromise, offering businesses and individuals in Russia the resources needed to detect and mitigate the impact of this malware.

Top charts for Mobile Android

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
6469020
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1305652
downloads
WinRAR

WinRAR

Latest update WinRAR download for free for Windows PC or Android mobile

5
735 reviews
501530
downloads
Minecraft

Minecraft

Latest update Minecraft download for free for Windows PC or Android mobile

5
750 reviews
454922
downloads

News and reviews for Mobile Android

Reducing Bloatware: Maximizing New Phone Experience

Transitioning to a new Pixel 10 Pro, users should critically assess bloatware and consider superior third-party apps for enhanced functionality.

Read more

Google Eases Sideloading Rules for Experienced Android Users

Google allows sideloading for experienced Android users, adjusting developer verification plans. Global rollout starts 2027.

Read more

Tandem Expands Mobi App to Android with FDA Clearance

Tandem Diabetes Care gains FDA clearance for its Android Mobi app, broadening U.S. market potential for automated insulin delivery.

Read more

Google Launches New Images Tab for iOS and Android

Google's app now features an Images tab, personalizing visual content on iOS and Android.

Read more

Google App Adds Personalized Images Tab for US Users

The Google app introduces a new Images tab for US Android and iOS users, offering a personalized visual feed.

Read more

Google Alters Android Sideloading Rules

Google revises sideloading policy for Android developers, responding to feedback from students, hobbyists, and power users.

Read more

Horizon: Steel Frontiers to Launch as Mobile MMO

Guerrilla Games and NCSoft reveal Horizon: Steel Frontiers, a mobile MMO in a post-apocalyptic world, built for PC and mobile devices.

Read more

India Promotes Local WhatsApp Alternative Amid Tech Push

India boosts support for an indigenous WhatsApp alternative, aiming to strengthen national tech infrastructure.

Read more

Launches Mobile App for Automated Trading

New TruTrade app on iOS & Android; enhances trading control for users via RipperONE AI.

Read more

Google Adds Developer Verification for Android Apps

Google requires developer verification for Android apps. The move aims to enhance user security and prevent scams, especially in Southeast Asia.

Read more