The story of programmer Kirill excited many: Monocle, an advanced FSB program for spying on volunteers and activists, was found on his smartphone.
Kirill received his phone back after 15 days of administrative arrest. He soon noticed a mysterious notification on the screen: “ Arm cortex vx3 synchronization .” An expert check showed that the smartphone actually contains a Monocle.
This spy software comes from St. Petersburg; It was developed by the Russian “Special Technology Center”, which is associated with Russian military intelligence (GRU), and which has been under US sanctions for “malicious cyber activity” for 8 years.
It is curious that the Monocle disguises itself as popular applications on Android phones so that it does not get noticed and is not taken down; — in particular, The Hacker News writes about the emergence of fake Signal, Skype and Evernote. Monocle can also disguise itself as system services with technical names so as not to arouse suspicion among users.
Researchers from Citizen Lab analyzed the case of Kirill P. and came to the conclusion: “Monocle” is not an ordinary malware virus, but a sophisticated surveillance tool.
Its capabilities are impressive:
Who should be afraid of the Monocle first?
It is important to note that it cannot be installed “over the air”: in order to be infected with this spyware, physical contact with your phone is required. Therefore, those who have encountered a situation where security forces took your smartphone and then returned it should think about the Monocle.
At the moment, only cases of infection of Android smartphones are known. However, iPhone owners also need to be on guard: Lookout researchers who analyzed the Monocle code found unused commands in it that may indicate the presence of a version of this spyware for Apple devices. 
You don't have to be a famous person to own a spy Monocle. As Kirill P.’s experience shows, this can affect anyone. This is in contrast to the Pegasus program, which, as a rule, is performed only on famous people, such as Galina Timchenko from Meduza.
How to recognize a Monocle infection: what to look for
Let's start with the battery - this is the first and most noticeable indicator of problems. Spyware constantly runs in the background, sending collected data to remote servers. This kind of activity requires energy—a lot of energy. If your phone suddenly begins to discharge two or three times faster than usual, and you have not installed new applications or changed your usage mode, this is a serious cause for concern. Discharge is especially noticeable in standby mode when you are not using the device.
The second important point is Internet traffic consumption. Modern spyware collects huge amounts of data: photographs, videos, recorded conversations, correspondence. All this needs to be somehow transferred to the “owners”; As a result, traffic grows exponentially. Check the statistics in your phone settings - if you see unexplained spikes in data consumption, especially at night or when you're not using your phone, it's time to sound the alarm.
The temperature of the device can also tell a lot. Spyware running in the background loads the processor. The phone may become noticeably warm even when at rest. Particularly indicative is heating in the upper part, where the camera is usually located - this may indicate its hidden use.
Often a spy is betrayed by oddities in the behavior of your smartphone: spontaneous turning on of the screen; unexpected sounds during conversations; sudden reboots; communication problems in places with good network coverage.
Unusual notifications or messages should definitely alert you, especially if they contain random sets of characters or technical terms (for example, the same “ Arm cortex vx3 synchronization ”).
Lifehacks for detecting spyware
What to do if your smartphone already clearly shows signs of spying?
If suspicions are confirmed, it is important to act quickly. First of all, turn on airplane mode - this will stop the data transfer and give you time to analyze the situation. Then save a backup copy of all important information, but be careful: this copy may already contain malicious software.
The most reliable solution is to completely reset the device to factory settings. This requires effort but will ensure maximum safety. After the reset, install the new firmware using your computer to eliminate the risk of being vulnerable again.
Bonus: checklist to protect your smartphone
Answer yourself these questions:
Did you install applications only from official stores?
Google Play and the App Store, despite all their shortcomings, at least check the programs you download.
Are your system and applications up to date?
Yes, updates are tedious, but hackers often exploit old vulnerabilities that have long been fixed in new versions.
Do you use strong passwords and two-factor authentication?
Use them wherever you can.
Are you checking the list of installed applications?
Remove everything suspicious and unfamiliar, especially programs that appeared recently or after the phone was in the wrong hands.
Have you read what permissions programs ask for during installation?
Go to settings and see what each app has access to. The calculator doesn't need access to the camera and microphone, the game doesn't need permission to send SMS, and the flashlight doesn't need to track your location. Any discrepancy between the functionality of the application and the requested permissions is a reason to be wary.