Saturday, August 15, 2026
LIVE
Ugandan villages still contest land titles as oil development advances///Nigerian Troops Repel Bandit Attack on Kebbi Workers///NLC Queries Lagos Chairman Over Ties to Pro-Tinubu Group///Côte d’Ivoire Names New Leader for Blé Goudé’s COJEP Party///United States Highlights Civilian Deaths in Nigeria Terror Fight///Zimbabwe Pledges New Ferry and Road Repair After Lake Kariba Disaster///Ebola death toll reaches two thousand in Democratic Republic of the Congo///Forced Conscription Reports Emerge Across Ethiopia Oromia Region///Ebola outbreak reaches displacement camps in eastern Democratic Republic of the Congo///Hacking Group Claims Data Theft from Shell and Other Global Firms///Turkey warns of radical measures if Israel rejects Gaza peace deal terms///Nigerian President Urged to Engage Niger Delta Leader for Reelection Campaign///Ugandan villages still contest land titles as oil development advances///Nigerian Troops Repel Bandit Attack on Kebbi Workers///NLC Queries Lagos Chairman Over Ties to Pro-Tinubu Group///Côte d’Ivoire Names New Leader for Blé Goudé’s COJEP Party///United States Highlights Civilian Deaths in Nigeria Terror Fight///Zimbabwe Pledges New Ferry and Road Repair After Lake Kariba Disaster///Ebola death toll reaches two thousand in Democratic Republic of the Congo///Forced Conscription Reports Emerge Across Ethiopia Oromia Region///Ebola outbreak reaches displacement camps in eastern Democratic Republic of the Congo///Hacking Group Claims Data Theft from Shell and Other Global Firms///Turkey warns of radical measures if Israel rejects Gaza peace deal terms///Nigerian President Urged to Engage Niger Delta Leader for Reelection Campaign///
Subscribe
Africa
Independent · Digital
The African Herald
PoliticsAI-assisted

ResidentBat Android Malware Grants Belarusian KGB Ongoing Mobile Access

ResidentBat is a custom Android spyware developed by the Belarusian KGB, used to convert seized smartphones into surveillance tools targeting journalists and civil society members.

ResidentBat is a custom Android spyware developed by the Belarusian KGB, used to convert seized smartphones into surveillance tools targeting journalists and civil society members.

This spyware operates outside the Play Store ecosystem and requires manual installation. It combines extensive data collection capabilities with remote control features, including the ability to remotely wipe devices.

Analysis by RSF’s Digital Security Lab attributes ResidentBat to the Belarusian KGB, indicating its use since at least 2021.

Initially disclosed in December 2025, ResidentBat was identified during a joint investigation by Reporters Without Borders and RESIDENT.NGO following the examination of a journalist's phone.

ResidentBat is sideloaded onto devices using the Android Debug Bridge (ADB) once physical possession is obtained. The installation process involves enabling USB debugging, sideloading the APK, manually granting permissions, and disabling Google Play Protect to avoid detection.

This method targets high-value individuals such as journalists and activists, sacrificing scale for precision.

ResidentBat is a custom Android spyware developed by the Belarusian KGB, used to convert seized smartphones into surveillance tools targeting journalists and civil society members.
Fatima Zerhouni · The African Herald

The spyware's command-and-control (C2) infrastructure supports data exfiltration, tasking, and configuration updates. It allows operators to manage compromised devices, collecting SMS, call logs, audio recordings, screen captures, encrypted messages, and local files.

Commands can be issued to adjust settings, retrieve data, or check device compliance, with the capability to invoke Android’s DevicePolicyManager.wipeData API for remote factory resets.

C2 Fingerprint and Internet-Scale Visibility

Censys research identifies a unique ResidentBat network fingerprint, enabling tracking of its infrastructure. Network defenders can detect ResidentBat activity through TLS telemetry, monitoring HTTPS sessions to self-signed endpoints on specific ports, or using documented banner hashes.

ResidentBat C2 servers typically use ports within the range of 7000–7257 and present self-signed TLS certificates. As of February 2026, ResidentBat-associated hosts have been identified in the Netherlands, Germany, Switzerland, and Russia.

Advertisement

Operators utilize defensive measures such as generic HTTP responses and possibly client certificate authentication. Certificate reuse across IP:port combinations aids in identifying related infrastructure.

For malware analysts, APK hashes from the RSF report facilitate correlation of new samples with known ResidentBat C2 endpoints.

Organizations supporting high-risk users should prioritize physical device security, USB debugging controls, and monitoring for unauthorized sideloaded packages and disabled Google Play Protect.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories