logo

SURXRAT Downloads Large LLM Module From Hugging Face

ID: 8ae8be42-9794-539c-942a-0009f003b7c6

STIX ID: report--8ae8be42-9794-539c-942a-0009f003b7c6

Feed Name: Cyble Blog

Threat Score
78/100

Date Published: 2026-02-24

Date Updated: 2026-07-16

...
...

**Executive summary:** SURXRAT V5 is a commercially distributed Android RAT sold via a Telegram MaaS ecosystem that provides extensive surveillance (SMS, contacts, call logs, location, browser history), remote device control (camera, audio, calls, clipboard, file access), a ransomware-style screen locker, and Firebase-based command-and-control; the operator offers reseller/partner licensing, over 180 samples were identified, and the latest variant conditionally downloads a very large LLM module (>23GB) from Hugging Face—suggesting experimentation with AI-enabled or evasion capabilities—while the report includes mitigation recommendations and IOCs for integration into threat feeds.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.