New malware Campaign delivers Android RAT
ID: c7031cb7-855d-5029-9bfe-07805a09d963
STIX ID: report--c7031cb7-855d-5029-9bfe-07805a09d963
Feed Name: Cyble Blog
Cyble Research Labs discovered an active Android RAT campaign (since March 2022, ~200+ samples) masquerading as legitimate apps; the malware requests numerous high-risk permissions and supports extensive spying capabilities (clipboard, SMS, call logs, location, audio/video capture, device identifiers), communicates with C2 at 8.tcp.ngrok.io:19742, exposes a list of commands for remote control, provides MITRE ATT&CK technique mappings, and supplies multiple file hashes as IoCs. The report recommends standard mobile hygiene (install only from official stores, use AV/MFA, review permissions, and factory reset if infected) and outlines detection/mitigation steps.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
