Rafel RAT targets outdated Android phones in ransomware attacks
ID: e65a7909-1144-5a4e-8bf8-5b28ceb2a16f
STIX ID: report--e65a7909-1144-5a4e-8bf8-5b28ceb2a16f
Feed Name: Bleeping Computer
Rafel RAT is an open-source Android malware used in 120+ campaigns that targets predominantly end-of-life Android devices (Android 11 and older) by luring victims to install malicious APKs via impersonated apps and platforms; it supports dangerous commands—ransomware (AES-based encryption and device locking), file wiping, SMS and 2FA exfiltration, and live location tracking—and has been observed in operations affecting government and military entities across multiple countries, with known actors (including APT-C-35) and ransom demands directed via Telegram. Recommended mitigations include avoiding sideloaded APKs, scanning apps with Play Protect, and keeping devices updated.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
