logo

Rapid Response: Zimperium’s Zero-Day Coverage of GhostBat RAT Campaign

ID: f95645ce-4e06-5387-985f-32ae9cc84acf

STIX ID: report--f95645ce-4e06-5387-985f-32ae9cc84acf

Feed Name: Zimperium Blog

Threat Score
70/100

Date Published: 2025-10-31

Date Updated: 2026-05-01

...
...

GhostBat RAT is an Android malware campaign targeting Indian users by impersonating Regional Transport Office (RTO) apps and luring victims via WhatsApp/SMS phishing and hosted APK links; once installed it uses fake update prompts, overlays, native libraries and multi-stage droppers to harvest banking credentials, SMS and device identifiers while evading detection. The report notes Zimperium detected related IOCs on-device (including a zero-day catch), highlighting the need for on-device mobile threat defenses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.