logo

Gravity RAT Malware Returns as A Chat Application

ID: b6dca338-0608-5ab6-83d7-7f609ebd6e9f

STIX ID: report--b6dca338-0608-5ab6-83d7-7f609ebd6e9f

Feed Name: Cyble Blog

Threat Score
70/100

Date Published: 2025-05-12

Date Updated: 2026-07-16

...
...

This report analyzes an Android Remote Administration Tool (Gravity RAT) disguised as a chat app called SoSafe Chat; it documents malicious behavior including reading and exfiltrating contacts, SMS, call logs, files, audio, and location, lists dangerous Android permissions abused, provides IOCs (SHA256 c7d01eac... and C2 https://api1.androidsdkstream.com/foxtrot/61c10953.php), shows source-code and traffic evidence of data upload to the C2, and notes distribution via phishing or a compromised sosafe.co.in site with tentative attribution to Pakistani-linked threat actors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.