SurxRAT Android Malware Uses LLMs for Phishing and Data Theft
ID: a2d286b1-108f-5530-a902-af17d0abe91c
STIX ID: report--a2d286b1-108f-5530-a902-af17d0abe91c
Feed Name: GBHackers
SurxRAT is a commercially distributed Android Remote Access Trojan marketed on Telegram as SURXRAT V5 and sold via reseller and partner licensing tiers, enabling affiliates to build and deploy customized malware. The RAT requests broad permissions and Accessibility privileges, exfiltrates SMS, contacts, call logs and device data, supports numerous remote control commands (including audio/camera capture and wiping), and includes a screen‑locker extortion module; it uses Firebase as C2 and conditionally downloads a >23GB LLM module, indicating growing sophistication and an expanding criminal ecosystem.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
