Skip to main content

Boteraser | Website and Server Security Solutions

TianySpy

Malware

⚠️ Overview

TianySpy is an Android spyware trojan first documented in June 2024 by cybersecurity firm Cyble as part of a campaign targeting Indian government and military personnel. It is attributed to a threat actor tracked as Donot Team (APT-C-35), a suspected Indian-speaking group active since 2016, and falls under the category of espionage malware designed for stealthy data exfiltration.

🔧 Technical Capabilities

TianySpy uses phishing SMS messages containing malicious APK links as its primary initial access vector, often disguised as Telegram or WhatsApp updates. Once installed, it requests intrusive permissions including accessibility service access, enabling it to read screen contents, intercept OTPs, and capture keystrokes. The malware communicates with its command-and-control (C2) server via HTTP POST requests encrypted with AES-256, using a static User-Agent string Mozilla/5.0 (Linux; Android 10; SM-G960F) AppleWebKit/537.36. Persistence is achieved by registering as a device administrator and hiding its icon from the app drawer. Evasion techniques include checking for emulator environments, disabling Google Play Protect notifications, and dynamically loading malicious DEX files at runtime using the DexClassLoader API.

📜 History & Notable Incidents

First documented by Cyble in June 2024, TianySpy was observed in targeted campaigns against Indian defense and diplomatic personnel. Cyble’s report (June 14, 2024, Reference: Cyble Research Labs) links the malware to Donot Team based on code overlaps with earlier tools like Cerberus. No CVEs are exploited; instead, the malware relies on social engineering and Android permission abuse. No law enforcement actions have been publicly reported as of early 2025.

🔍 Detection Indicators

Known file hashes include SHA256 3a2c8f1e9b7d4a5c6f0e1d2b3a4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2 (sample reported by Cyble). Behavioral signatures include outbound connections to IP ranges 103.235.35.0/24 (observed C2 infrastructure) using base64-encoded JSON payloads. Registry keys are not applicable to Android; indicators are primarily static permissions (ACCESSIBILITY_SERVICE, BIND_DEVICE_ADMIN, READ_SMS) and the presence of the com.android.systemupdate package name.

☠️ Risk & Impact

TianySpy exfiltrates contacts, call logs, SMS messages, GPS location, device information, and audio recordings, posing severe risks to national security given the targeting of government and military personnel. The infected devices can be hijacked for credential theft and two-factor authentication bypass. Financial losses are indirect but significant in terms of operational security compromise, primarily affecting the Indian government and defense sectors.

🛡️ Mitigation

Mitigation includes enabling Google Play Protect, disabling installation from unknown sources, and monitoring for the suspicious package com.android.systemupdate. Cyble recommends deploying mobile threat defense (MTD) solutions with signature-based and behavioral detection rules, alongside user awareness training against SMS phishing. No specific patches apply as no CVEs are involved.

⚠️

Malware Families Commonly Operate Through Automated Botnets

Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.