DogeRAT: The Android Malware Campaign Targeting Users Across Multiple Industries
ID: fbcd65b9-2f4f-5bc6-9ecb-e4cf49b879b0
STIX ID: report--fbcd65b9-2f4f-5bc6-9ecb-e4cf49b879b0
Feed Name: CloudSEK Blog
**DogeRAT Android RAT campaign**: CloudSEK TRIAD discovered a widespread scam campaign distributing a Java-based Android Remote Access Trojan (DogeRAT) disguised as legitimate apps across social media and messaging platforms, primarily targeting banking and entertainment users in India but with global reach; the RAT uses a Telegram bot as a C2 panel (with Node.js server-side glue), requests intrusive permissions (SMS, call logs, audio, camera), displays legitimate webviews to appear authentic, and is linked to over a thousand counterfeit apps with many SHA1 indicators of compromise provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
