logo

Airavat Malware: Sophisticated RAT & Ransomware Targeting Android

ID: 6051e57b-fbad-52e3-aa45-0b80dc8d48dc

STIX ID: report--6051e57b-fbad-52e3-aa45-0b80dc8d48dc

Feed Name: Cyble Blog

Threat Score
78/100

Date Published: 2025-05-20

Date Updated: 2026-07-16

...
...

Cyble Research Labs analyzed an AIRAVAT Android RAT (including a Pro variant) being distributed via opendir sites and sold on Telegram; the RAT uses Firebase C2 and grants broad permissions to exfiltrate SMS, calls, contacts, audio and camera data, execute shell commands, send SMS, delete files and perform ransomware encryption/decryption. The report includes technical details, command mappings, app metadata, multiple file hashes and C2/distribution URLs as IOCs, and highlights the malware's ease of use and active distribution among threat actors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.