GoatRAT: Banking Trojan Targeting Brazil
ID: cee3a449-f357-5a53-9823-6f824baedeac
STIX ID: report--cee3a449-f357-5a53-9823-6f824baedeac
Feed Name: Cyble Blog
Threat Score
CRIL analyzed a GoatRAT Android banking-trojan variant that abuses Android Accessibility and overlay permissions to automate unauthorized PIX instant-pay transfers from Brazilian banking apps (NUBank, Banco Inter, PagBank). The report includes APK metadata (SHA256), behavioral details of ATS implementation, distribution and C2 URLs (bit.ly shortlink, goatrat.com, api.goatrat.com:3008), and recommended mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
