logo

SURXRAT, a Trojan’s LLM-Driven Expansion in Android Malware

ID: 3c27103c-f905-5cc8-86e5-e61fe1b93cb5

STIX ID: report--3c27103c-f905-5cc8-86e5-e61fe1b93cb5

Feed Name: The Cyber Express

Threat Score
75/100

Date Published: 2026-02-25

Date Updated: 2026-04-23

Author: Ashish Khaitan

...
...

SURXRAT V5 is an Android Remote Access Trojan sold through a Telegram-based malware-as-a-service operation offering Reseller and Partner licensing tiers; researchers have identified over 180 samples and promotional claims of widespread registration. Functionally, SURXRAT abuses high-risk permissions and Android Accessibility Services to exfiltrate SMS, contacts, call logs, browser history, and other device data to a Firebase backend (noted as xrat-sisuriya-default-rtdb), supports remote audio/camera capture and device control, includes a ransomware-style screen locker for extortion, and conditionally downloads a >23GB LLM module (from Hugging Face) under configurable triggers—indicating active commercialized cybercrime with evolving AI experimentation and significant privacy/fraud risks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.