logo

Deep Dive Analysis – capraRAT

ID: c29eecc3-7633-59f3-9bc1-c1653f2ef7c9

STIX ID: report--c29eecc3-7633-59f3-9bc1-c1653f2ef7c9

Feed Name: Cyble Blog

Threat Score
88/100

Date Published: 2025-11-17

Date Updated: 2026-07-16

...
...

Cyble Research Labs analysed capraRAT, an Android Remote Access Trojan attributed to Pakistan-linked APT36, which masquerades as a legitimate app, hides its icon, communicates with a C2 at http://android.viral91.xyz/admin/webservices, and can exfiltrate contacts, SMS, call logs, location, screenshots, camera images, and audio; the report includes a SHA256 (d9979a4...) and recommended mitigations for users and organisations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.