logo

Rafel RAT, Android Malware from Espionage to Ransomware Operations

ID: 7e7db3aa-f9c8-53c0-9efa-9d392f443e62

STIX ID: report--7e7db3aa-f9c8-53c0-9efa-9d392f443e62

Feed Name: Check Point Research

Threat Score
78/100

Date Published: 2024-06-20

Date Updated: 2026-04-27

Author: [email protected]

...
...

**Executive summary:** Check Point Research analyzed Rafel RAT, an open-source Android remote administration tool actively used in ~120 phishing campaigns to perform data exfiltration (contacts, SMS/2FA, call logs), device surveillance and control, and ransomware/file-wipe operations; the report provides technical analysis of its services, C2 PHP panel behavior, commands, evasion techniques, victim demographics (device models, Android versions, countries), and IoCs including SHA256 hashes and C2 domains, and documents misuse of hacked infrastructure to host the RAT.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.