Android Spyware BouldSpy Linked to Iranian Government

A new Android surveillance tool discovered by mobile security experts at Zimperium has been attributed to the Islamic Republic of Iran’s (FARAJA) Law Enforcement Command.

Dubbed BouldSpy, the mobile malware has been used by threat actors to target minority groups and potentially those involved in illegal trafficking activities, according to an advisory released by the company on Wednesday.

“BouldSpy has extensive surveillance capabilities, including recording calls, capturing photos, and monitoring account usernames across multiple platforms,” ​​explained Zimperium security researcher Nicolás Chiaraviglio.

BouldSpy keeps your app alive by disabling battery management and setting CPU activation locks while leveraging Android Accessibility Services to perform most of its monitoring actions.

“By abusing CPU locks and disabling battery management features, the spyware prevents the device from shutting down its activities, causing faster battery drain for victims,” ​​Chiaraviglio explained.

“Once installed, BouldSpy establishes a network connection to its command and control server (C2) and exfiltrates cached data from the victim’s device. A background service handles most of the functionality of monitoring and restarts when the user or the Android system stops its main activity.

Zimperium has warned that BouldSpy is very risky for both individuals and the general public due to its advanced surveillance capabilities.

“Selective surveillance of minority groups in Iran may lead to further discrimination and suppression, amplifying existing social and political tensions,” Chiaraviglio wrote.

At the time of writing, Zimperium has observed a limited number of BouldSpy samples, all of which are distributed outside of the Google Play Store via third-party services.

“Spyware has not been distributed through Google Play, which makes it more difficult for users to identify and avoid. Also, this shows the danger of loading apps from unknown third-party sources,” he said Chiaraviglio.

Zimperium’s warning comes weeks after the threat actor known as Mint Sandstorm was observed weaponizing N-day vulnerabilities to target US critical infrastructure.

