logo

DogeRAT: The Android Malware Campaign Targeting Users Across Multiple Industries

ID: fbcd65b9-2f4f-5bc6-9ecb-e4cf49b879b0

STIX ID: report--fbcd65b9-2f4f-5bc6-9ecb-e4cf49b879b0

Feed Name: CloudSEK Blog

Threat Score
72/100

Date Published: 2023-05-29

Date Updated: 2026-04-27

...
...

**DogeRAT Android RAT campaign**: CloudSEK TRIAD discovered a widespread scam campaign distributing a Java-based Android Remote Access Trojan (DogeRAT) disguised as legitimate apps across social media and messaging platforms, primarily targeting banking and entertainment users in India but with global reach; the RAT uses a Telegram bot as a C2 panel (with Node.js server-side glue), requests intrusive permissions (SMS, call logs, audio, camera), displays legitimate webviews to appear authentic, and is linked to over a thousand counterfeit apps with many SHA1 indicators of compromise provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.