logo

Extended Rapid Response: Zimperium’s Zero-Day Coverage of Oblivion RAT

ID: d856f00c-2f80-5896-b576-f3f9121b3f4e

STIX ID: report--d856f00c-2f80-5896-b576-f3f9121b3f4e

Feed Name: Zimperium Blog

Threat Score
75/100

Date Published: 2026-03-21

Date Updated: 2026-05-01

...
...

Zimperium zLabs analyzed Oblivion RAT, a new Android remote-access trojan sold as a MaaS that employs pixel-perfect social-engineering lures and Accessibility Service abuse to grant itself dangerous permissions, uses ZIP-format anti-analysis tricks to thwart static tools, and provides operators with VNC, keylogging, SMS/2FA interception and automated targeting of financial apps; researchers found additional low-coverage variants and published IOCs while noting on-device behavioral detection provides effective protection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.