logo

Ratel RAT targets outdated Android phones in ransomware attacks

ID: 55ac512c-84d0-54a8-b016-77e479e3a3e2

STIX ID: report--55ac512c-84d0-54a8-b016-77e479e3a3e2

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2024-06-22

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Check Point researchers analyzed the widespread Android malware Rafel RAT, used in more than 120 campaigns to target primarily end-of-life Android devices (≤ Android 11). Operators distribute fake APKs impersonating legitimate apps, request risky permissions to persist, and remotely execute commands including file encryption (ransomware), device locking, wiping, SMS/2FA exfiltration, and live location tracking; roughly 10% of observed infections triggered the ransomware command. The activity has targeted high-profile organizations including government and military entities across the US, China, and Indonesia, and involves both known APTs (e.g., APT-C-35) and criminal groups.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.