Malware
PlainGnome
According to Lookout, PlainGnome consists of a two-stage deployment in which a very minimal first stage drops a malicious APK once it’s installed.
PlainGnome is a Android malware family operated by Gamaredon Group.
Background
Lookout explains that PlainGnome uses a two-stage approach: a stripped-down first stage installs and then drops a malicious APK. Between January 2024 and at least October, the second-stage payload's code changed substantially, with the developers adopting Jetpack WorkManager classes to manage exfiltration, simplifying development and upkeep. WorkManager also lets them set conditions for execution; for instance, PlainGnome only pulls data off a victim's device while it sits idle, likely to avoid alerting the user to its presence. Unlike the lightweight installer stage, the second stage handles all of the surveillance and requests 38 permissions.
Source: Malpedia (Fraunhofer FKIE).