logo

PJobRAT Malware Targets Users in Taiwan via Fake Apps

ID: d7db6a4d-6aae-5581-9b4c-435573c570c0

STIX ID: report--d7db6a4d-6aae-5581-9b4c-435573c570c0

Feed Name: Infosecurity Magazine (News)

Threat Score
70/100

Date Published: 2025-03-27

Date Updated: 2026-04-22

...
...

Researchers uncovered a long-running cyber-espionage campaign distributing PJobRAT — an Android RAT disguised as chat apps hosted on compromised WordPress sites — that exfiltrates SMS, contacts and media, executes shell commands (enabling rooting and lateral actions), records audio, and communicates via Firebase Cloud Messaging and HTTP C2; activity spanned at least Jan 2023 to Oct 2024 and targeted users in Taiwan (previously seen against Indian military).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.