Oblivion RAT Turns Fake Play Store Updates Into a Full-Service Android Spyware Operation
ID: 095b0192-bfd1-5eca-a43f-d5c35e66febe
STIX ID: report--095b0192-bfd1-5eca-a43f-d5c35e66febe
Feed Name: cybersecurityNews.com
**Executive Summary:** Oblivion RAT is a commercially offered Android remote access trojan (MaaS) that uses a fake Google Play update dropper and a two-stage implant to gain silent, full-device control via AccessibilityService hijacking, enabling keystroke logging, SMS/OTP interception, VNC sessions, and targeted theft of financial data; researchers obtained samples and builders, identified IOCs (e.g., com.darkpurecore*, com.oblivion.dropper.MainActivity, payload.apk.xz), and warn organizations to restrict sideloading and monitor suspicious Accessibility usage.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
