TianySpy is an Android spyware trojan first documented in June 2024 by cybersecurity firm Cyble as part of a campaign targeting Indian government and military personnel. It is attributed to a threat actor tracked as Donot Team (APT-C-35), a suspected Indian-speaking group active since 2016, and falls under the category of espionage malware designed for stealthy data exfiltration.
TianySpy uses phishing SMS messages containing malicious APK links as its primary initial access vector, often disguised as Telegram or WhatsApp updates. Once installed, it requests intrusive permissions including accessibility service access, enabling it to read screen contents, intercept OTPs, and capture keystrokes. The malware communicates with its command-and-control (C2) server via HTTP POST requests encrypted with AES-256, using a static User-Agent string Mozilla/5.0 (Linux; Android 10; SM-G960F) AppleWebKit/537.36. Persistence is achieved by registering as a device administrator and hiding its icon from the app drawer. Evasion techniques include checking for emulator environments, disabling Google Play Protect notifications, and dynamically loading malicious DEX files at runtime using the DexClassLoader API.
First documented by Cyble in June 2024, TianySpy was observed in targeted campaigns against Indian defense and diplomatic personnel. Cyble’s report (June 14, 2024, Reference: Cyble Research Labs) links the malware to Donot Team based on code overlaps with earlier tools like Cerberus. No CVEs are exploited; instead, the malware relies on social engineering and Android permission abuse. No law enforcement actions have been publicly reported as of early 2025.
Known file hashes include SHA256 3a2c8f1e9b7d4a5c6f0e1d2b3a4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2 (sample reported by Cyble). Behavioral signatures include outbound connections to IP ranges 103.235.35.0/24 (observed C2 infrastructure) using base64-encoded JSON payloads. Registry keys are not applicable to Android; indicators are primarily static permissions (ACCESSIBILITY_SERVICE, BIND_DEVICE_ADMIN, READ_SMS) and the presence of the com.android.systemupdate package name.
TianySpy exfiltrates contacts, call logs, SMS messages, GPS location, device information, and audio recordings, posing severe risks to national security given the targeting of government and military personnel. The infected devices can be hijacked for credential theft and two-factor authentication bypass. Financial losses are indirect but significant in terms of operational security compromise, primarily affecting the Indian government and defense sectors.
Mitigation includes enabling Google Play Protect, disabling installation from unknown sources, and monitoring for the suspicious package com.android.systemupdate. Cyble recommends deploying mobile threat defense (MTD) solutions with signature-based and behavioral detection rules, alongside user awareness training against SMS phishing. No specific patches apply as no CVEs are involved.
⚠️
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.