logo

Multiple Threat Actors Deploying Open-Source Rafel RAT to Target Android Devices

ID: 64886075-395d-572b-a9ec-623122f0b8e5

STIX ID: report--64886075-395d-572b-a9ec-623122f0b8e5

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2024-06-24

Date Updated: 2026-05-08

Author: [email protected] (The Hacker News)

...
...

Check Point analysis found widespread misuse of the open-source Android remote administration tool Rafel RAT—masqueraded as popular apps and delivered via social engineering and malicious PDFs—across ~120 campaigns spanning many countries; the RAT can steal SMS (including 2FA), contacts, location and notifications, manipulate/wipe devices, supports HTTP(S)/Discord C2 and a PHP control panel, and has been used by both APT (DoNot Team / APT-C-35) and criminal operators in ransomware operations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.