ResidentBat Android Malware Grants Belarusian KGB Ongoing Mobile Access
ResidentBat is a custom Android spyware developed by the Belarusian KGB, used to convert seized smartphones into surveillance tools targeting journalists and civil society members.
ResidentBat is a custom Android spyware developed by the Belarusian KGB, used to convert seized smartphones into surveillance tools targeting journalists and civil society members.
This spyware operates outside the Play Store ecosystem and requires manual installation. It combines extensive data collection capabilities with remote control features, including the ability to remotely wipe devices.
Analysis by RSF’s Digital Security Lab attributes ResidentBat to the Belarusian KGB, indicating its use since at least 2021.
Initially disclosed in December 2025, ResidentBat was identified during a joint investigation by Reporters Without Borders and RESIDENT.NGO following the examination of a journalist's phone.
ResidentBat is sideloaded onto devices using the Android Debug Bridge (ADB) once physical possession is obtained. The installation process involves enabling USB debugging, sideloading the APK, manually granting permissions, and disabling Google Play Protect to avoid detection.
This method targets high-value individuals such as journalists and activists, sacrificing scale for precision.
ResidentBat is a custom Android spyware developed by the Belarusian KGB, used to convert seized smartphones into surveillance tools targeting journalists and civil society members.
The spyware's command-and-control (C2) infrastructure supports data exfiltration, tasking, and configuration updates. It allows operators to manage compromised devices, collecting SMS, call logs, audio recordings, screen captures, encrypted messages, and local files.
Commands can be issued to adjust settings, retrieve data, or check device compliance, with the capability to invoke Android’s DevicePolicyManager.wipeData API for remote factory resets.
C2 Fingerprint and Internet-Scale Visibility
Censys research identifies a unique ResidentBat network fingerprint, enabling tracking of its infrastructure. Network defenders can detect ResidentBat activity through TLS telemetry, monitoring HTTPS sessions to self-signed endpoints on specific ports, or using documented banner hashes.
ResidentBat C2 servers typically use ports within the range of 7000–7257 and present self-signed TLS certificates. As of February 2026, ResidentBat-associated hosts have been identified in the Netherlands, Germany, Switzerland, and Russia.
Operators utilize defensive measures such as generic HTTP responses and possibly client certificate authentication. Certificate reuse across IP:port combinations aids in identifying related infrastructure.
For malware analysts, APK hashes from the RSF report facilitate correlation of new samples with known ResidentBat C2 endpoints.
Organizations supporting high-risk users should prioritize physical device security, USB debugging controls, and monitoring for unauthorized sideloaded packages and disabled Google Play Protect.
Based on reporting by GBHackers.



