1、Unmasking State-Sponsored Mobile Surveillance Malware from Russia,China,and North KoreaThreat Actors,Tactics,and Defense Strategies1Kyle SchmittleAlemdar IslamogluKristina Balaam#BHEU BlackHatEventsAlemdar IslamogluSenior Staff Security Intelligence ResearcherNorth Korea and Middle East.Hermit,Bould
2、Spy and GuardZooReverse engineering,penetration testing,and security software development.https:/ BalaamSenior Staff Security Intelligence ResearcherCampaigns initiated by Chinese threat actors.DragonEgg/WyrmSpy,MOONSHINE&Android BadBazaarPassion for uncovering threats that target marginalized popul
3、ations within mainland China and abroad.https:/ Who We AreKyle SchmittleSenior Security Intelligence ResearcherRussia&IranBouldSpy,GuardZooThreat intelligence,reverse engineeringhttps:/ BlackHatEvents I-Overview of the Mobile APT Landscape Russia,China,North Korea II-APTs and Their Tricks Accessing
4、Devices Detection Countermeasures Whos Under Attack How We Attribute ActivityAgenda3#BHEU BlackHatEvents III-Takeaways Fingerprints of State-Backed Surveillance Mitigation Techniques Call to ActionAgenda4I-Overview of the Mobile APT LandscapeRussia,China,North Korea5Mobile APT Groups:Russia#BHEU Bla
5、ckHatEventsMobile APT Groups:RussiaMonokleBoneSpy Infamous ChiselPlainGnome2019202220242023#BHEU BlackHatEventsMobile APT Groups:RussiaMonokleDeveloper-STCUsed by Likely Turla(FSB Center 16)BoneSpy Infamous ChiselPlainGnome2019202220242023#BHEU BlackHatEventsMobile APT Groups:Russia2019202220242023M
6、onokleDeveloper-STCUsed by Likely Turla(FSB Center 16)BoneSpy Based on DroidWatcherUsed by Gamaredon(FSB Center 18)Infamous ChiselPlainGnome#BHEU BlackHatEventsMobile APT Groups:RussiaMonokleDeveloper-STCUsed by Likely Turla(FSB Center 16)BoneSpy Based on DroidWatcherUsed by Gamaredon(FSB Center 18)