Fantasy Hub: Another Russian Based RAT as M-a-a-S
ID: 0e1dd120-5027-557c-af82-45276e77d575
STIX ID: report--0e1dd120-5027-557c-af82-45276e77d575
Feed Name: Zimperium Blog
Fantasy Hub is an actively marketed Android Remote Access Trojan offered as a Malware-as-a-Service that enables broad device takeover and espionage: it uses counterfeit Google Play pages for distribution, a native dropper that decrypts payloads at runtime, abuse of the SMS handler to intercept 2FA and messages, WebRTC for live audio/video streaming, and customizable phishing overlays to steal banking credentials; the seller provides builders, Telegram-based subscription and notification tooling, and instructions that lower the barrier to novice attackers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
