Rapid Response: Zimperium’s Zero-Day Coverage of GhostBat RAT Campaign
ID: f95645ce-4e06-5387-985f-32ae9cc84acf
STIX ID: report--f95645ce-4e06-5387-985f-32ae9cc84acf
Feed Name: Zimperium Blog
GhostBat RAT is an Android malware campaign targeting Indian users by impersonating Regional Transport Office (RTO) apps and luring victims via WhatsApp/SMS phishing and hosted APK links; once installed it uses fake update prompts, overlays, native libraries and multi-stage droppers to harvest banking credentials, SMS and device identifiers while evading detection. The report notes Zimperium detected related IOCs on-device (including a zero-day catch), highlighting the need for on-device mobile threat defenses.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
