ResidentBat — Belarusian KGB Android Spyware at Internet Scale (ADB Sideloading, Custom HTTPS C2, Journalist & Civil Society Targeting)

ResidentBat — Belarusian KGB Android Spyware at Internet (TL-2026-0143), also tracked as ResidentBat, is a high-severity malware campaign, first published 2026-02-25. It is attributed to Belarusian KGB (Belarus) with high confidence, affects Google Android, maps to 20 MITRE ATT&CK techniques (T1422, T1426, T1429), and is covered by 9 detection rules and 16 indicators of compromise.

Key facts for TL-2026-0143

Threat ID
TL-2026-0143
Also known as
ResidentBat, THREAT-240
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
2026-02-25
Last reviewed
2026-02-25
Attribution
Belarusian KGB
Attribution confidence
HIGH
Nation-state nexus
Belarus
Motivation
ESPIONAGE
Target sectors
media, civil-society, journalism, human-rights, government-opposition
Target regions
Belarus, Eastern Europe, Europe
Detection rules
9
Indicators of compromise
16

Malware and tooling in ResidentBat — Belarusian KGB Android Spyware at Internet

Malware and tooling: ResidentBat

ResidentBat is an Android spyware implant attributed to the Belarusian KGB (State Security Committee), used for targeted surveillance against journalists and civil society. Deployed via physical access and ADB sideloading during KGB interrogations, it exfiltrates SMS, call logs, encrypted messenger data, microphone recordings, screen captures, and files. C2 infrastructure uses HTTPS with self-signed certificates (CN=server) on port range 7000-7257 with a distinctive banner fingerprint. Censys identified 10 active C2 nodes across Netherlands (5), Germany (2), Switzerland (2), and Russia (1). Development dates back to at least 2021. Includes remote wipe via DevicePolicyManager.wipeData.

How ResidentBat — Belarusian KGB Android Spyware at Internet works

ResidentBat is a nation-state Android spyware implant attributed to the Belarusian KGB, representing a serious threat to press freedom and civil liberties. First publicly documented in December 2025 by Reporters Without Borders (RSF) and RESIDENT.NGO, with internet-scale C2 infrastructure analysis published by Censys in February 2026.

The malware was detected on the smartphone of a journalist who had been questioned by the KGB. During interrogation at KGB premises, the journalist was required to place the smartphone in a locker and show content on the device, unlocking the phone in an officer's presence. RSF and the journalist believe that security forces observed the PIN entry, retrieved the phone during questioning, and installed the spyware via ADB sideloading.

Distribution model is entirely physical-access based — ResidentBat is NOT distributed via the C2. Installation requires: (1) physical access to the target device, (2) ADB (Android Debug Bridge) sideloading of the APK, (3) manual granting of permissions by the attacker, (4) Google Play Protect disabled by the attacker. This hands-on deployment model limits scale but enables highly targeted, persistent surveillance against specific individuals.

Once installed, ResidentBat provides operators comprehensive surveillance capabilities: exfiltration of SMS messages and call logs, access to encrypted messenger data (Signal, Telegram, WhatsApp), real-time and on-demand microphone recording, screen capture, file access and exfiltration, remote command execution, device status queries, and critically — remote wipe via DevicePolicyManager.wipeData to erase evidence.

Configuration is delivered via JSON and includes parameters: server address (sars), upload period (spd), and 'upload data ASAP' flag (asp). The malware masquerades as a regular system app to avoid detection.

C2 infrastructure analysis by Censys reveals distinctive technical characteristics: HTTPS protocol with self-signed certificates (CN=server, typically 3-year validity), narrow port range 7000-7257 for control traffic (some endpoints on 4022), consistent TLS/HTTP banner hash (SHA-256: 6f6676d369e99d61ce152e1e2b2eb6f5e26a4331f4008b5d6fe567edefdbeaca). C2 servers employ hardening: catch-all 200 OK responses with empty bodies for all HTTP paths, static or fake Date headers for anti-forensics, likely client certificate authentication embedded in APK, and server-side device allowlisting.

As of February 2026, Censys identified 10 ResidentBat C2 hosts: Netherlands (5), Germany (2), Switzerland (2), Russia (1). Infrastructure is concentrated in European VPS/datacenter providers and Russian ASNs. Dominant AS: AS29182 (RU-JSCIOT), with AS210976 (TWC-EU), AS44812, AS51395, AS44051 also represented. 5 distinct certificate SHA-256 fingerprints observed with certificate reuse across IP:port endpoints enabling infrastructure clustering.

Code analysis suggests development dates back to at least 2021, with additional variants identified via antivirus platform sample comparison. Parts of the code contain English-language strings, suggesting possible third-party development or design for use beyond Belarus. RSF shared findings with Google, which issued 'government-backed attack' threat notifications to identified targets.

Belarus currently ranks 166th of 180 countries in the 2025 RSF World Press Freedom Index. 32 journalists are currently imprisoned. ResidentBat is part of systematic repression of independent journalism in Belarus under Lukashenko's regime.

MITRE ATT&CK techniques used in TL-2026-0143

Discovery

T1422 System Network Configuration Discovery; T1426 System Information Discovery

Collection

T1429 Audio Capture; T1513 Screen Capture; T1533 Data from Local System; T1636.002 Protected User Data: Call Log; T1636.003 Protected User Data: Contact List; T1636.004 Protected User Data: SMS Messages

Command and Control

T1437.001 Application Layer Protocol: Web Protocols; T1481.002 Web Service: Bidirectional Communication; T1509 Non-Standard Port

Impact

T1464 Network Denial of Service

Initial Access

T1474 Supply Chain Compromise; T1476 Deliver Malicious App via Other Means

Credential Access

T1517 Access Notifications

Persistence

T1541 Foreground Persistence

Defense Evasion

T1628.001 Hide Artifacts: Suppress Application Icon; T1655 Masquerading

defense-evasion

T1630.002 File Deletion

Exfiltration

T1646 Exfiltration Over C2 Channel

Affected products and versions in ResidentBat — Belarusian KGB Android Spyware at Internet

  • Google — Android
    Vulnerable versions: All versions with ADB debugging enabled

Remediation for ResidentBat — Belarusian KGB Android Spyware at Internet

Immediate actions

  • Block outbound HTTPS to known ResidentBat C2 IPs on ports 7000-7257 and 4022
  • Alert on TLS connections to servers presenting CN=server (self-signed) on ports 7000-7257
  • Block banner hash: 6f6676d369e99d61ce152e1e2b2eb6f5e26a4331f4008b5d6fe567edefdbeaca
  • Monitor for ADB usage and sideloaded packages on managed Android devices
  • Alert on Google Play Protect being disabled on managed devices

Workarounds

  • Never leave devices unattended during border crossings or official interactions in Belarus
  • Use secondary/burner devices for travel to Belarus and neighboring countries
  • Enable device encryption and strong biometric authentication
  • Monitor for unknown apps with system-level permissions
  • Contact RSF Digital Security Lab if surveillance suspected

Longer-term hardening

  • Enable Android Advanced Protection Mode (AAPM) for at-risk users — blocks sideloading entirely
  • Disable USB debugging on all production/personal devices
  • Implement device handling protocols for journalists in high-risk environments (border crossings, interrogations)
  • Deploy mobile threat defense (MTD) with ADB sideloading detection
  • Use Censys Threat Module (THREAT-240) for ongoing C2 infrastructure tracking

Weaknesses (CWE) in ResidentBat — Belarusian KGB Android Spyware at Internet

CWE-306, CWE-200, CWE-295

Timeline of ResidentBat — Belarusian KGB Android Spyware at Internet

  • Code analysis suggests ResidentBat development began at least as early as 2021. Earliest known variant identified via antivirus platform sample comparison.
  • Believed to be in active operational use by Belarusian KGB against journalists and civil society. Multiple variants deployed over time.
  • ResidentBat detected on smartphone of journalist questioned by KGB. Spyware installed during interrogation at KGB premises via ADB sideloading while device was in locker.
  • Antivirus flagged suspicious components on journalist's device. RESIDENT.NGO and RSF Digital Security Lab perform forensic analysis confirming ResidentBat implant.
  • RSF and RESIDENT.NGO publish joint report attributing ResidentBat to Belarusian KGB. Technical PDF report details capabilities and C2 infrastructure. Source: https://rsf.org/en/exclusive-rsf-uncovers-new-spyware-belarus
  • RSF shares research with Google. Google issues 'government-backed attack' threat notifications to identified targets of ResidentBat campaign.
  • Censys maps ResidentBat infrastructure: 10 hosts, ports 7000-7257, 5 distinct certificate fingerprints, dominant AS29182 (RU-JSCIOT). Banner hash and TLS fingerprint enable detection at internet scale.
  • Censys publishes internet-scale C2 infrastructure analysis. Identifies 10 active C2 hosts across Netherlands, Germany, Switzerland, and Russia. Creates Threat Module THREAT-240. Source: https://censys.com/blog/residentbat-belarusian-kgb-android-spyware/
  • As of 2026-05-29, ResidentBat remains ACTIVE: Censys (THREAT-240, 2026-02-24) tracked 10 live KGB C2 hosts (NL/DE/CH/RU) with no takedown, sanctions, or CISA advisory since. No CVE exists to patch (physical-access ADB sideloading), and the attributing Belarusian KGB actor stays operational with no disruption reported.

Sources cited for ResidentBat — Belarusian KGB Android Spyware at Internet

Threats related to ResidentBat — Belarusian KGB Android Spyware at Internet

Detection coverage for TL-2026-0143

As of 2026-02-25, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0143 across Splunk SPL, Microsoft KQL and Sigma, covering 16 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats