Monokle is an Android spyware family associated with the Russian contractor Special Technology Centre (STC) and used for covert surveillance and data theft on compromised mobile devices. It has been publicly linked to Russian state-aligned interests and has been described as custom Android spyware with extensive collection capabilities and tradecraft oriented toward long-term monitoring of targets.
Monokle supports broad on-device surveillance, including recording keystrokes, capturing microphone audio and phone calls, taking photos and videos, retrieving contact lists and call history, enumerating installed applications, and collecting device metadata such as make, model, power state, and network connectivity. It can also access locally stored data useful for profiling and credential recovery, including browser history, user dictionaries, user-defined shortcuts, and password-storage salt values that may assist an operator in deriving a victim’s plaintext password or PIN from stored hashes. Reported variants or closely related samples have additionally shown capabilities such as screen capture, extraction of messages from other applications, shell command execution, JavaScript injection, device-administrator abuse, and real-time audio/video streaming.
The spyware has been noted for using Android accessibility features to facilitate surveillance, including keylogging, and for exfiltration methods designed to operate effectively even without root access. It also includes anti-forensic and cleanup functionality: Monokle can delete arbitrary files, uninstall itself, and remove staging artifacts from the device. These behaviors support both operational security and defense evasion.
Observed deployment has included trojanized Android applications masquerading as legitimate software. A documented 2024 case involved a malicious application covertly implanted on an Android device after physical confiscation by Russian authorities, with researchers assessing the implant as either an updated Monokle variant or new spyware substantially reusing Monokle code and command structure. This case underscores Monokle’s use in targeted surveillance scenarios against individuals of intelligence interest rather than indiscriminate mass infection.
Monokle is best characterized as a mobile espionage platform focused on Android devices, combining collection, credential-related theft, profiling, and stealth features suitable for persistent surveillance of dissidents, activists, or other high-value targets.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The spyware bears many similarities to the Monokle family of spyware, previously reported on by Lookout Mobile Security... suggesting that it is either an updated version of Monokle or new software created by reusing much of the same code.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
The second stage contains many common spyware capabilities, including: Location Tracking Screen capture Keylogging Recording calls
Gooligan steals authentication tokens that can be used to access data from multiple Google applications. RCSAndroid can collect passwords for Wi-Fi networks and online accounts, including Skype, Facebook, Twitter, Google, WhatsApp, Mail, and LinkedIn. Monokle can retrieve the salt used when storing the user’s password, aiding an adversary in computing the user’s plaintext password/PIN from the stored password hash.
Monokle checks if the device is connected via Wi-Fi or mobile data; Pegasus for Android checks if the device is on Wi-Fi, a cellular network, and is roaming; TianySpy can check to see if Wi‑Fi is enabled; TERRACOTTA can check if the active network connection is metered; TrickMo can collect device network configuration information such as IMSI, IMEI, and Wi‑Fi connection state.
Anubis can exfiltrate files encrypted with the ransomware module from the device and can modify external storage. BusyGasper can collect images stored on the device and browser history. CHEMISTGAMES can collect files from the filesystem and account information from Google Chrome.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Advanced mobile spyware for Android, observed here as a trojanized Cube Call Recorder app. It can track location, record calls, capture screens, log keystrokes, read messages from encrypted apps, extract files and stored passwords, execute shell commands, and add device administrator privileges. The report assesses the sample as either an updated Monokle variant or new spyware heavily reusing Monokle code.
Spyware installed on an Android device after seizure by the FSB, used for surveillance of a civilian target and attributed through technical artifact analysis by Citizen Lab.
Advanced Android spyware capable of exfiltrating data without root, leveraging accessibility services, performing AiTM attacks, searching for keywords, and recording locked screens to steal credentials. Used in highly targeted attacks.
Software changes: Monokle
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.