A new Android malware disguised as antivirus software is causing cybersecurity concerns . According to a report by Russian security firm Dr. Web , the spyware – codenamed Android.Backdoor.916.origin – is posing as security software from Russia’s Federal Security Service (FSB) and is targeting executives at Russian businesses .
A malicious software with a… patriotic orientation
Researchers found the software distributed via applications that supposedly offer virus protection, but in reality it does not include any such functionality. Instead, once installed, it gains access to a wealth of sensitive user data. The application interface is available only in Russian, which clearly indicates that the spyware is designed exclusively for targeted attacks within Russia.
See also: QuirkyLoader helps distribute infostealer malware
The branding used by its creators is also important: in some cases, it appears under the name “GuardCB”, referring to the Central Bank of Russia, while in other cases it bears names such as “SECURITY_FSB” or “ФСБ”, giving the impression that it comes from the Russian secret services. In this way, it tries to gain the trust of victims and prevent its removal.

From fake scans to full device control
One of the most typical methods of deception is the “scan” of the device. When the user presses the corresponding button, the application displays false results: in about 30% of cases it reports that it has detected from 1 to 3 “threats”, creating the illusion of a real antivirus.
Behind this deceptive screen, however, lies a powerful surveillance tool. Android.Backdoor.916.origin requests a number of high-risk permissions, including access to SMS, calls, multimedia, geolocation, microphone, and camera. Through these, it can:
- Export SMS, contacts, call history and photos.
- Activate microphone and camera, recording environment and conversations.
- Record keystrokes (keylogging) and extract data from popular applications such as Telegram, WhatsApp, Gmail, Chrome and Yandex.
- Execute shell-style commands, maintaining access even if the user tries to disable it.
Dr. Web highlights that the development of Android malware continues, with new versions appearing continuously from January 2025 to the present. This indicates an organized and long-term effort by the perpetrators to target Russian businesses.
See also: Misusing Microsoft Help Index Files to execute PipeMagic malware
Resilience and infrastructure
Another worrying feature is the malware's ability to connect to up to 15 different hosting providers. While this feature is not active in the current version, it demonstrates that the software is designed for maximum resilience against detection and neutralization attempts.
Indicators of Compromise (IoCs) have been published by Dr. Web in a relevant GitHub repository, so that security experts can identify and address potential infections in a timely manner.

New Android malware: What does it mean for the business world?
For Russian businesses, the existence of such spyware means that the risks of confidential data leaks are enormous. Strategic information, financial data, and even personal conversations of executives can fall into the wrong hands. Dr. Web warns that companies must strengthen security measures their, paying particular attention to mobile devices, which until recently were often underestimated as a source of risk.
Globally, the case highlights an even more worrying trend: the use of spyware that mimics applications from government agencies.
See also: Phishing: Noodlophile malware distribution with new “bait”
Android.Backdoor.916.origin is not just another piece of malware. It is a sign of how cyberthreats are evolving, becoming more strategic. For Android users – and especially business executives – the message is clear: installing apps from untrusted sources can open the door to organized and extremely dangerous attacks.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
In a world where information is the most valuable currency, this spyware proves that the data war is now in our hands – literally, inside the devices we carry every day.
Source: www.bleepingcomputer.com
