Gravity RAT Malware Returns as A Chat Application
ID: b6dca338-0608-5ab6-83d7-7f609ebd6e9f
STIX ID: report--b6dca338-0608-5ab6-83d7-7f609ebd6e9f
Feed Name: Cyble Blog
This report analyzes an Android Remote Administration Tool (Gravity RAT) disguised as a chat app called SoSafe Chat; it documents malicious behavior including reading and exfiltrating contacts, SMS, call logs, files, audio, and location, lists dangerous Android permissions abused, provides IOCs (SHA256 c7d01eac... and C2 https://api1.androidsdkstream.com/foxtrot/61c10953.php), shows source-code and traffic evidence of data upload to the C2, and notes distribution via phishing or a compromised sosafe.co.in site with tentative attribution to Pakistani-linked threat actors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
