The Rise of Arsink Rat
ID: 99f0dd6e-d38b-5363-bf73-0b771f67985a
STIX ID: report--99f0dd6e-d38b-5363-bf73-0b771f67985a
Feed Name: Zimperium Blog
Arsink is a cloud-native Android RAT campaign that aggressively harvests sensitive data (SMS including OTPs, call logs, contacts, microphone recordings, photos, and device identifiers) and offers remote control and destructive actions. Operators distribute deceptive APKs via social-engineered channels (Telegram, Discord, MediaFire) while abusing legitimate cloud services (Firebase RTDB/Storage, Google Apps Script/Drive, Telegram Bot API) for C2 and exfiltration; analysis documents large scale (≈1,216 unique APKs, 317 Firebase endpoints, ≈45,000 infected IPs across 143 countries) and coordinated takedown efforts with Google, while warning that rapid variant churn and cloud-abuse maintain continued risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
