SURXRAT, a Trojan’s LLM-Driven Expansion in Android Malware
ID: 3c27103c-f905-5cc8-86e5-e61fe1b93cb5
STIX ID: report--3c27103c-f905-5cc8-86e5-e61fe1b93cb5
Feed Name: The Cyber Express
SURXRAT V5 is an Android Remote Access Trojan sold through a Telegram-based malware-as-a-service operation offering Reseller and Partner licensing tiers; researchers have identified over 180 samples and promotional claims of widespread registration. Functionally, SURXRAT abuses high-risk permissions and Android Accessibility Services to exfiltrate SMS, contacts, call logs, browser history, and other device data to a Firebase backend (noted as xrat-sisuriya-default-rtdb), supports remote audio/camera capture and device control, includes a ransomware-style screen locker for extortion, and conditionally downloads a >23GB LLM module (from Hugging Face) under configurable triggers—indicating active commercialized cybercrime with evolving AI experimentation and significant privacy/fraud risks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
