logo

Oblivion RAT - An Android Spyware Platform With a Built-In APK Factory

ID: 28d8f5af-5a8f-5484-9742-4536d39c67c5

STIX ID: report--28d8f5af-5a8f-5484-9742-4536d39c67c5

Feed Name: iVerify Blog

Threat Score
78/100

Date Published: 2026-03-03

Date Updated: 2026-04-28

...
...

Oblivion RAT is a commercially offered Android Remote Access Trojan sold as MaaS that uses a two-stage sideloading dropper and a fake Accessibility Settings flow to auto-grant permissions, enabling VNC, keylogging, SMS interception (including OTPs), default SMS handler hijack, and app-targeting 'Wealth Assessment'; the report includes builder/C2 access, samples, anti-analysis techniques (fake ZIP encryption flag), multiple IoCs (IPs, domain, hashes), and mapped MITRE ATT&CK techniques.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.