ResidentBat is an Android spyware implant attributed to Belarus’s State Security Committee (KGB) and used in surveillance operations against journalists, activists, and broader civil society. Public reporting indicates it has been in use since at least 2021 and is associated with cases in which targets’ phones were confiscated during detention or interrogation, after which the implant was installed through hands-on access rather than remote exploitation. Deployment has been linked to Android Debug Bridge sideloading of an application package, manual permission granting, and disabling of Google Play Protect, indicating an operator-controlled installation workflow on seized devices.
Once installed, ResidentBat provides extensive monitoring and collection capabilities on compromised Android phones. Documented functions include access to call logs, SMS messages, encrypted messenger content, microphone audio recording, screenshot or screen-content capture, and collection of locally stored files. The implant also supports remote operator tasking, configuration updates, device-status queries, and remote wiping, enabling both persistent surveillance and post-compromise control over the device.
ResidentBat communicates with command-and-control infrastructure over HTTPS and appears designed to resist straightforward internet-scale fingerprinting at the HTTP layer, suggesting deliberate operational hardening. Its command infrastructure is used for configuration management, command delivery, updates, and receipt of exfiltrated data rather than initial infection.
ResidentBat is part of a broader pattern of state use of endpoint spyware against detained members of civil society. Its known use is closely tied to Belarusian repression of independent journalism and dissent, with targeting focused on individuals whose devices could yield communications, files, and other sensitive personal or organizational information.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Last year, Reporters Without Borders disclosed a previously unknown spyware tool, dubbed ResidentBat, that was discovered on the phone of a Belarusian journalist who believed the malware had been installed while they were detained by Belarus' KGB.
Belarus’s KGB was linked to ResidentBat, active since at least 2021, used to pull call logs and stored files from detained activists.
In December 2025, Reporters Without Borders (RSF) identified a previously unknown spyware called ResidentBat, which it assessed Belarus’s State Security Committee (KGB) had used since at least 2021 to access call logs, SMS messages, and locally stored files on the devices of detained activists and journalists.
ResidentBat is an Android spyware implant used by the Belarusian KGB for surveillance operations against journalists and civil society.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Previously unknown spyware discovered on the phone of a Belarusian journalist.
Spyware linked to Belarus’s KGB that extracts call logs and stored files from detained activists’ devices.
Previously unknown spyware used to access call logs, SMS messages, and locally stored files on targeted devices.
Android spyware/implant reportedly deployed via physical access and ADB sideloading; enables surveillance and data theft including call logs, microphone recordings, SMS, encrypted messenger traffic, screen captures, and local file access.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.