logo

Rapid Response: Zimperium’s Full Detection for RatOn — NFC Heists, Remote Control, and Automated Transfers

ID: 592c40f1-24c0-534c-aa69-64011a97d152

STIX ID: report--592c40f1-24c0-534c-aa69-64011a97d152

Feed Name: Zimperium Blog

Threat Score
78/100

Date Published: 2025-09-10

Date Updated: 2026-05-01

...
...

RatOn is an advanced Android banking Trojan campaign targeting Czech and Slovak users that combines NFC relay attacks, overlay-based phishing, and remote access Trojan capabilities with an Automated Transfer System (ATS) to perform automated fraudulent transfers. Delivered via adult-themed malicious domains, the dropper abuses Accessibility Services and Device Admin privileges to stealthily install and persist, enabling real-time control of banking and crypto wallet apps (e.g., MetaMask, Trust, Blockchain.com, Phantom), overlay or text-based remote interfaces, and optional device locking for ransom; Zimperium reports detection coverage for public samples.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.