ResidentBat — Belarusian KGB Android Spyware at Internet Scale (ADB Sideloading, Custom HTTPS C2, Journalist & Civil Society Targeting) — Threadlinqs Intelligence
As of 2026-05-30, ResidentBat — Belarusian KGB Android Spyware at Internet Scale (ADB Sideloading, Custom HTTPS C2, Journalist & Civil Society Targeting) is a high-severity malware threat attributed to Belarusian KGB (Belarus), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 16 indicators of compromise.
Threat ID: TL-2026-0143 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Attribution: Belarusian KGB · Belarus · ESPIONAGE
ResidentBat is an Android spyware implant attributed to the Belarusian KGB (State Security Committee), used for targeted surveillance against journalists and civil society. Deployed via physical
ResidentBat is a nation-state Android spyware implant attributed to the Belarusian KGB, representing a serious threat to press freedom and civil liberties. First publicly documented in December 2025 by Reporters Without Borders (RSF) and RESIDENT.NGO, with internet-scale C2 infrastructure analysis published by Censys in February 2026.
The malware was detected on the smartphone of a journalist who had been questioned by the KGB. During interrogation at KGB premises, the journalist was required to place the smartphone in a locker and show content on the device, unlocking the phone in an officer's presence. RSF and the journalist believe that security forces observed the PIN entry, retrieved the phone during questioning, and installed the spyware via ADB sideloading.
Distribution model is entirely physical-access based — ResidentBat is NOT distributed via the C2. Installation requires: (1) physical access to the target device, (2) ADB (Android Debug Bridge) sideloading of the APK, (3) manual granting of permissions by the attacker, (4) Google Play Protect disabled by the attacker. This hands-on deployment model limits scale but enables highly targeted, persistent surveillance against specific individuals.
Once installed, ResidentBat provides operators comprehensive surveillance capabilities: exfiltration of SMS messages and call logs, access to encrypted messenger data (Signal, Telegram, WhatsApp), real-time and on-demand microphone recording, screen capture, file access and exfiltration, remote command execution, device status queries, and critically — remote wipe via DevicePolicyManager.wipeData to erase evidence.
Configuration is delivered via JSON and includes parameters: server address (sars), upload period (spd), and 'upload data ASAP' flag (asp). The malware masquerades as a regular system app to avoid detection.
C2 infrastructure analysis by Censys reveals distinctive technical characteristics: HTTPS protocol with self-signed certificates (CN=server, typically 3-year validity), narrow port range 7000-7257 for control traffic (some endpoints on 4022), consistent TLS/HTTP banner hash (SHA-256: 6f6676d369e99d61ce152e1e2b2eb6f5e26a4331f4008b5d6fe567edefdbeaca). C2 servers employ hardening: catch-all 200 OK responses with empty bodies for all HTTP paths, static or fake Date headers for anti-forensics, likely client certificate authentication embedded in APK, and server-side device allowlisting.
As of February 2026, Censys identified 10 ResidentBat C2 hosts: Netherlands (5), Germany (2), Switzerland (2), Russia (1). Infrastructure is concentrated in European VPS/datacenter providers and Russian ASNs. Dominant AS: AS29182 (RU-JSCIOT), with AS210976 (TWC-EU), AS44812, AS51395, AS44051 also represented. 5 distinct certificate SHA-256 fingerprints observed with certificate reuse across IP:port endpoints enabling infrastructure clustering.
Code analysis suggests development dates back to at least 2021, with additional variants identified via antivirus platform sample comparison. Parts of the code contain English-language strings, suggesting possible third-party development or design for use beyond Belarus. RSF shared findings with Google, which issued 'government-backed attack' threat notifications to identified targets.
Belarus currently ranks 166th of 180 countries in the 2025 RSF World Press Freedom Index. 32 journalists are currently imprisoned. ResidentBat is part of systematic repression of independent journalism in Belarus under Lukashenko's regime.
Weaknesses (CWE)
CWE-306, CWE-200, CWE-295
Target sectors: media, civil-society, journalism, human-rights, government-opposition
Target regions: Belarus, Eastern Europe, Europe
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 16 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1476, T1474, T1541, T1655, T1628.001, T1517, T1426, T1422, T1636.004, T1636.002