The Belarusian KGB is the state security and intelligence service of Belarus and has been linked to the deployment of mobile spyware against domestic journalists. Reported activity includes the use of ResidentBat spyware on smartphones during or shortly after police interrogations. This spyware has been associated with surveillance functions including collection of call logs and messages, audio recording, screenshot capture, and file exfiltration. Observed infrastructure associated with this spyware has been active since 2021, aligning with the period of intensified repression following anti-government protests in Belarus. In this context, the Belarusian KGB is associated with politically motivated domestic surveillance and intelligence collection targeting members of the press.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 malware family attributed to this actor across reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.