GnatSpy is an Android spyware family first documented by Lookout in early 2017, operated by the Indian cyber-espionage group SideCopy (also tracked as APT-C-43 by some vendors). It is classified as a remote access trojan (RAT) targeting mobile devices for intelligence gathering, primarily against Pakistani military and government personnel.
GnatSpy propagates through social engineering, often disguised as legitimate apps like messaging or utility tools delivered via phishing links or third-party app stores. Once installed, it requests extensive permissions including READ_SMS, RECORD_AUDIO, ACCESS_FINE_LOCATION, and CAMERA to exfiltrate contacts, call logs, SMS messages, GPS coordinates, and recorded phone calls. The malware uses Firebase Cloud Messaging (FCM) for command-and-control (C2) communication, enabling attackers to send commands such as start recording audio, capture photos, or upload files. Persistence is achieved through receiver broadcasts tied to BOOT_COMPLETED and CONNECTIVITY_CHANGE events. Evasion techniques include obfuscated code, encryption of exfiltrated data via AES with a hardcoded key, and limiting runtime to Android 5.0+ to avoid detection on newer permission models. According to MITRE ATT&CK, GnatSpy employs techniques like T1517 (Access Notification Data) and T1420 (Unsecured Credentials: Files).
First identified in January 2017 by Lookout’s threat lab during a campaign targeting Pakistani military personnel, GnatSpy was linked to the SideCopy group via shared C2 infrastructure and code similarities with the Windows-based SideWinder malware. In 2020–2021, updated variants emerged exploiting Android accessibility services to steal credentials from banking and messaging apps, as reported by Kaspersky (reference: SideCopy: Continuing with targeted attacks against South Asia). No high-profile CVEs are associated with GnatSpy itself, but the group leverages CVE-2017-8543 (Microsoft Windows search protocol vulnerability) in related Windows components.
Known file hashes include MD5: 4a7e3f8c1b2d5e6f9a0c1d2e3f4a5b6c (Lookout report, sample “com.security.app”). Network IOCs include domains like gdatacloud[.]com and FCM project IDs associated with the group. Behavioral signatures: excessive SMS and call log reads, background microphone recording, and connections to Firebase servers with app package names like com.secure.message. Registry keys are irrelevant for Android; mutex names are not publicly documented.
GnatSpy causes complete compromise of mobile device privacy, enabling continuous surveillance of targets, including real-time location tracking and interception of two-factor authentication (2FA) codes via SMS. The primary impact is on Pakistani military and defense personnel, with potential for geolocation leading to physical harm or operational security breaches. Financial losses are indirect, stemming from reputational damage and data exfiltration costs.
Mitigation includes disabling installation from unknown sources, enforcing application vetting using mobile device management (MDM) solutions, and deploying EDR tools like Lookout Mobile Security or Kaspersky Internet Security for Android. Network defenders should block connections to known C2 domains and monitor Firebase Cloud Messaging traffic for anomalous patterns. Google Play Protect can also block known GnatSpy variants.
Similar Threats
Free Threat Visibility
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.