Deep Dive Analysis – capraRAT
ID: c29eecc3-7633-59f3-9bc1-c1653f2ef7c9
STIX ID: report--c29eecc3-7633-59f3-9bc1-c1653f2ef7c9
Feed Name: Cyble Blog
Threat Score
Cyble Research Labs analysed capraRAT, an Android Remote Access Trojan attributed to Pakistan-linked APT36, which masquerades as a legitimate app, hides its icon, communicates with a C2 at http://android.viral91.xyz/admin/webservices, and can exfiltrate contacts, SMS, call logs, location, screenshots, camera images, and audio; the report includes a SHA256 (d9979a4...) and recommended mitigations for users and organisations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
