Analysis of cifrat: could this be an evolution of a mobile RAT?
ID: bd2d3dde-21f2-5d13-8010-e0052a973d92
STIX ID: report--bd2d3dde-21f2-5d13-8010-e0052a973d92
Feed Name: CERT Polska
**CERT Polska** analysed a multi-stage Android malware campaign that lures victims with a Booking.com-themed phishing site to sideload a malicious APK; the dropper uses a native JNI decoder and encrypted stages to install a final accessibility-controlled RAT that supports credential capture, HTML overlay/phishing, SMS exfiltration, screen and camera streaming, remote gestures, and SOCKS5 relaying, communicating over split WebSocket control/data channels to otptrade.world; the report includes detailed technical analysis, unpacking helpers, anti-analysis findings, and IOCs (URLs, package names, file hashes).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
