News: 0177127091

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

New Android Spyware Is Targeting Russian Military Personnel On the Front Lines (arstechnica.com)

(Thursday April 24, 2025 @11:30PM (BeauHD) from the behind-the-scenes dept.)


An anonymous reader quotes a report from Ars Technica:

> Russian military personnel are being [1]targeted with recently discovered Android malware that steals their contacts and tracks their location. The malware is hidden inside a modified app for Alpine Quest mapping software, which is used by, among others, hunters, athletes, and Russian personnel stationed in the war zone in Ukraine. The app displays various topographical maps for use online and offline. The trojanized Alpine Quest app is being pushed on a dedicated Telegram channel and in unofficial Android app repositories. The chief selling point of the trojanized app is that it provides a free version of Alpine Quest Pro, which is usually available only to paying users.

>

> The malicious module is named Android.Spy.1292.origin. In a [2]blog post , researchers at Russia-based security firm Dr.Web wrote: "Because Android.Spy.1292.origin is embedded into a copy of the genuine app, it looks and operates as the original, which allows it to stay undetected and execute malicious tasks for longer periods of time. Each time it is launched, the trojan collects and sends the following data to the C&C server:

>

> - the user's mobile phone number and their accounts;

> - contacts from the phonebook;

> - the current date;

> - the current geolocation;

> - information about the files stored on the device;

> - the app's version."

>

> If there are files of interest to the threat actors, they can update the app with a module that steals them. The threat actors behind Android.Spy.1292.origin are particularly interested in confidential documents sent over Telegram and WhatsApp. They also show interest in the file locLog, the location log created by Alpine Quest. The modular design of the app makes it possible for it to receive additional updates that expand its capabilities even further.



[1] https://arstechnica.com/security/2025/04/russian-military-personnel-on-the-front-lines-targeted-with-new-android-spyware/

[2] https://news.drweb.com/show/?i=15006&lng=en&c=5



Awesome (Score:3)

by Baron_Yam ( 643147 )

Sounds like an excellent targeting system.

ha ha (Score:2)

by Local ID10T ( 790134 )

/nelson

Seriously? Front line infantry are relying on pirate versions of android apps on their phones for basic navigation/orienteering? That says a lot. None of it good.

Re:ha ha (Score:5, Insightful)

by Big Hairy Gorilla ( 9839972 )

My take on that is that soldiers are just regular people.. who have no idea whatsoever goes on in a phone or what the current state of phones are.

Here's an idea, lets all use Telegram to plan our next ... whatever... bombing? Or like at the Pentagon. Hey! lets all use Signal to plan our next bombing.

So a Russian soldier is about as tech savvy as the people running the Pentagon?

Yeah, I agree, none of that can be good. ;-(

Re: (Score:2)

by alvinrod ( 889928 )

If it beats the alternatives what do you expect. Unless the enemy is tapped in and can warn their own soldiers about the attack before your side can execute it, it's immaterial. If you know that they know you can even use it to your advantage to call in a fake attack to get them to react to it. If you're not assuming that your communications are compromised on some level you're probably deluding yourself anyway. Even if you do have a secure system at the start of a conflict, expecting it to remain secure is

Re: (Score:2)

by stabiesoft ( 733417 )

From reporting I've seen, most on the front lines are not regular people. They are people allowed out of prison in exchange for a get out of jail free card. The slaughter is so bad that prisoners are declining and then being forced. And then we have the other "regular" people from NK that are being shipped over to be cannon fodder. It is ugly, and really just f*cked up that trump is saying putin is listening and wants peace the day after putin lobbed a major attack on Kiev I think it was using NK missiles.

Re:ha ha (Score:4, Funny)

by PPH ( 736903 )

> Front line infantry are relying on pirate versions of android apps on their phones for basic navigation/orienteering?

That's nothing. Russian fighter-bombers have been seen with [1]civilian grade GPS units [globaldefensecorp.com] duct taped to their instrument panel.

Allowing advanced western technology to fall into Russian hands is unconscionable. Who let them get hold of duct tape?

[1] https://www.globaldefensecorp.com/2022/06/21/exposed-captured-russian-pilots-admit-that-russian-air-force-distributed-garmin-gps-and-pronebo-mobile-app-to-navigate-in-ukraine/

Re: (Score:2)

by Rujiel ( 1632063 )

"...and here's how Ukraine can still win!"

Re: (Score:2)

by Rujiel ( 1632063 )

"Having Putin's asset in the Whitehouse sure is making it hard for the Ukrainians today"

The plan was already to do some "stakeholder capitalism" on Ukraine and have Blackrock take its land. This was already the plan with the expectation that Ukraine would win. The US has used Ukraine as a dumping ground for waste, as a host for biological warfare facilities, and as a source for human sex and organ trafficking. The goal was never for Ukraine to be prosperous, but for it to be profitable, and for it to be a s

do something fun like make them text an premium ra (Score:2)

by Joe_Dragon ( 2206452 )

do something fun like make them text an premium rate sms service that gives all funds to the ukraine

Re: (Score:2)

by Mr. Dollar Ton ( 5495648 )

Done already in 2023 iirc.

So... Ukraine, spying on Russian soldiers? (Score:3)

by 93 Escort Wagon ( 326346 )

Or Russia, following the old KGB playbook?

Fine's Corollary:
Functionality breeds Contempt.