GhostBat RAT: Inside The Resurgence Of RTO-Themed Android Malware
ID: 2c764a20-d3e7-507f-9f3f-069d435dd60d
STIX ID: report--2c764a20-d3e7-507f-9f3f-069d435dd60d
Feed Name: Cyble Blog
**GhostBat RAT (RTO-themed Android campaign)** — Cyble CRIL observed an active Android malware campaign that distributes malicious mParivahan APKs via WhatsApp, smishing (shortened URLs), GitHub-hosted APKs and compromised websites; uses multi-stage droppers, ZIP header manipulation, native packers and JNI-based obfuscation to evade analysis; installs a malicious mParivahan app that phishes for mobile/vehicle details and UPI PINs, exfiltrates SMS messages (filtering for banking keywords), can forward SMS/OTPs, registers devices via a Telegram bot, and includes a cryptocurrency miner; the report includes technical TTPs and extensive IOCs (SHA-256 hashes, download URLs, short URLs, Telegram and Firebase endpoints).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
