logo

New malware Campaign delivers Android RAT

ID: c7031cb7-855d-5029-9bfe-07805a09d963

STIX ID: report--c7031cb7-855d-5029-9bfe-07805a09d963

Feed Name: Cyble Blog

Threat Score
75/100

Date Published: 2025-05-20

Date Updated: 2026-07-16

...
...

Cyble Research Labs discovered an active Android RAT campaign (since March 2022, ~200+ samples) masquerading as legitimate apps; the malware requests numerous high-risk permissions and supports extensive spying capabilities (clipboard, SMS, call logs, location, audio/video capture, device identifiers), communicates with C2 at 8.tcp.ngrok.io:19742, exposes a list of commands for remote control, provides MITRE ATT&CK technique mappings, and supplies multiple file hashes as IoCs. The report recommends standard mobile hygiene (install only from official stores, use AV/MFA, review permissions, and factory reset if infected) and outlines detection/mitigation steps.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.