
On December 4, “First Department” told the story of programmer and anti-war activist Kirill Parubets. He was detained by the FSB, subjected to threats, arrest and recruitment, and then discovered spyware on his smartphone, created on the instructions of the special services. This software is called "Monocle". We'll tell you what it can do, how it can end up in your device, and what you need to do to prevent this from happening.
Monocle is a family of spyware developed by order of the FSB. It is a sophisticated, custom set of tools that allows intelligence attackers to gain access to electronic devices such as mobile phones and tablets.
Simply put, Monocle is software for spying on people.
In 2019, American cybersecurity experts from Lookout published a report in which they talked about the Monocle spy program. It is alleged that the Monocle could be used to penetrate smartphones (running Android) of people interested in Islam, Syrian rebels, residents of the Caucasus and users of the Uzbek messenger UzbekChat.
In 2024, “First Department” talked about the first known case of using the Monocle to spy on anti-war activists - spy software was installed on the smartphone of programmer Kirill Parubets after detention, seizure of equipment, arrest and brutal recruitment.
The simple answer is we don't know because we only know about a small number of confirmed and suspected infections.
But we know something else: cyberspy imitates both popular services such as Google Play, Skype and Signal, as well as supposedly “system” programs, which the average person, even if detected, most likely would not think of checking for malware, much less removing.
The First Department does not have information about cases of devices being infected using so-called zero-click attacks, when infection occurs without the knowledge of the victim, who did not need to follow links or download files. We believe that the main method of infection may be, as in the case of Kirill Parubets, installation via a cable in “extreme” situations when the device ends up in the hands of specialists from the FSB.
For example, this can happen during border crossings, where the FSB often randomly interrogates people. Or - another option: using social engineering to trick the target of security forces into downloading and installing the program themselves.
In fact, the Monocle allows attackers to gain full access to their target's device.
There is probably an iOS version of the Monocle. Researchers from Lookout found unused commands in the program that indicate the presence of a version of cyberspyware for Apple devices.
We assume that attacks on iPhone users are also possible.
The First Department knows that the Monocle is a cyber espionage tool used by the FSB.
According to the Lookout report, the malicious program was developed at the St. Petersburg “Special Technology Center”, which cooperates with the Russian defense industry, produces radio monitoring equipment and systems and supplies drones, cell phone signal jammers and other special equipment to law enforcement agencies.
In 2016, Barack Obama imposed sanctions against STC. The press release on the White House website said little about STC - that the company assisted the General Staff in conducting electronic intelligence.
In the case described by the First Department, cyber spyware was installed on the smartphone of anti-war activist Kirill Parubets. The FSB tried to persuade Parubets to cooperate - to force him to monitor his friend, against whom a case of treason was being prepared.
The “monocle” in this case performed two functions:
First of all, we recommend paying attention to unusual behavior of your device. For example, if your battery suddenly began to run out quickly, or services appeared that you did not install.
In the case of Kirill Parubets, Monocle was disguised as a system service with a name that was difficult for the average person.
We also advise you to regularly check the applications installed on your phone and monitor their permissions. If you find something that has a lot of permissions, and you don’t know where you got this service from, contact the First Department.
You can contact us via Telegram bot or email: [email protected]