logo

Analysis of cifrat: could this be an evolution of a mobile RAT?

ID: bd2d3dde-21f2-5d13-8010-e0052a973d92

STIX ID: report--bd2d3dde-21f2-5d13-8010-e0052a973d92

Feed Name: CERT Polska

Threat Score
78/100

Date Published: 2026-04-03

Date Updated: 2026-04-19

Author: Kacper Ratajczak

...
...

**CERT Polska** analysed a multi-stage Android malware campaign that lures victims with a Booking.com-themed phishing site to sideload a malicious APK; the dropper uses a native JNI decoder and encrypted stages to install a final accessibility-controlled RAT that supports credential capture, HTML overlay/phishing, SMS exfiltration, screen and camera streaming, remote gestures, and SOCKS5 relaying, communicating over split WebSocket control/data channels to otptrade.world; the report includes detailed technical analysis, unpacking helpers, anti-analysis findings, and IOCs (URLs, package names, file hashes).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.