logo

'Cellik' Android RAT Leverages Google Play Store

ID: 43edc913-fa4d-585a-9fc9-40365de87d45

STIX ID: report--43edc913-fa4d-585a-9fc9-40365de87d45

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2025-12-17

Date Updated: 2026-04-21

Author: Alexander Culafi

...
...

The report describes Cellik, a commercial Android RAT-as-a-service that wraps payloads in legitimate Play Store apps and offers features such as full remote device control, screen streaming, keylogging, notification and OTP capture, file system and cloud access, malicious overlay injection, and an automatic APK builder to facilitate sideload distribution; it highlights Play Protect evasion claims, low cost of access for attackers, and recommended defenses like avoiding sideloading and using endpoint/mobile security.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.