logo

Oblivion RAT Turns Fake Play Store Updates Into a Full-Service Android Spyware Operation

ID: 095b0192-bfd1-5eca-a43f-d5c35e66febe

STIX ID: report--095b0192-bfd1-5eca-a43f-d5c35e66febe

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-03-23

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

**Executive Summary:** Oblivion RAT is a commercially offered Android remote access trojan (MaaS) that uses a fake Google Play update dropper and a two-stage implant to gain silent, full-device control via AccessibilityService hijacking, enabling keystroke logging, SMS/OTP interception, VNC sessions, and targeted theft of financial data; researchers obtained samples and builders, identified IOCs (e.g., com.darkpurecore*, com.oblivion.dropper.MainActivity, payload.apk.xz), and warn organizations to restrict sideloading and monitor suspicious Accessibility usage.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.