logo

Android and Windows RATs Distributed Via Online Meeting Lures

ID: 993b52e2-2bc9-545b-84d9-cb148d02777b

STIX ID: report--993b52e2-2bc9-545b-84d9-cb148d02777b

Feed Name: Security Boulevard

Threat Score
70/100

Date Published: 2024-03-05

Date Updated: 2026-04-22

Author: Himanshu Sharma

...
...

Zscaler ThreatLabz discovered an active campaign (Dec 2023–Jan 2024) in which a threat actor hosted multiple fraudulent Skype/Google Meet/Zoom websites on a shared IP to distribute RATs: SpyNote APKs for Android and NjRAT/DCRat for Windows. Users who click Android or Windows download links receive malicious APKs or BAT files that fetch and execute RAT payloads (some delivered as packed WinRAR archives), with open directories exposing additional executables; the report includes observed domains, filenames, sandbox detections, and mapped MITRE ATT&CK techniques.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.