Rafel RAT, Android Malware from Espionage to Ransomware Operations
ID: 7e7db3aa-f9c8-53c0-9efa-9d392f443e62
STIX ID: report--7e7db3aa-f9c8-53c0-9efa-9d392f443e62
Feed Name: Check Point Research
**Executive summary:** Check Point Research analyzed Rafel RAT, an open-source Android remote administration tool actively used in ~120 phishing campaigns to perform data exfiltration (contacts, SMS/2FA, call logs), device surveillance and control, and ransomware/file-wipe operations; the report provides technical analysis of its services, C2 PHP panel behavior, commands, evasion techniques, victim demographics (device models, Android versions, countries), and IoCs including SHA256 hashes and C2 domains, and documents misuse of hacked infrastructure to host the RAT.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
