logo

SurxRAT Shows How Mobile Malware Can Leverage Large-Language Models

ID: 7fe59ed3-4f7f-5eba-b99c-7712d58d6d7a

STIX ID: report--7fe59ed3-4f7f-5eba-b99c-7712d58d6d7a

Feed Name: Zimperium Blog

Threat Score
70/100

Date Published: 2026-03-09

Date Updated: 2026-05-01

...
...

A recent analysis identifies SurxRAT, an Android remote-access trojan that can download and run third-party large language model modules (e.g., from Hugging Face) to automate malicious tasks. By integrating LLMs, SurxRAT can craft realistic phishing content, perform tailored social-engineering prompts, and autonomously interact with on-device apps and user interfaces to exfiltrate credentials and sensitive data, increasing evasion and persistence and underscoring the need for behavior-based detection and strict app controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.