logo

GhostBat RAT: Inside The Resurgence Of RTO-Themed Android Malware

ID: 2c764a20-d3e7-507f-9f3f-069d435dd60d

STIX ID: report--2c764a20-d3e7-507f-9f3f-069d435dd60d

Feed Name: Cyble Blog

Threat Score
75/100

Date Published: 2025-11-28

Date Updated: 2026-07-17

...
...

**GhostBat RAT (RTO-themed Android campaign)** — Cyble CRIL observed an active Android malware campaign that distributes malicious mParivahan APKs via WhatsApp, smishing (shortened URLs), GitHub-hosted APKs and compromised websites; uses multi-stage droppers, ZIP header manipulation, native packers and JNI-based obfuscation to evade analysis; installs a malicious mParivahan app that phishes for mobile/vehicle details and UPI PINs, exfiltrates SMS messages (filtering for banking keywords), can forward SMS/OTPs, registers devices via a Telegram bot, and includes a cryptocurrency miner; the report includes technical TTPs and extensive IOCs (SHA-256 hashes, download URLs, short URLs, Telegram and Firebase endpoints).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.