Multiple Threat Actors Deploying Open-Source Rafel RAT to Target Android Devices
ID: 64886075-395d-572b-a9ec-623122f0b8e5
STIX ID: report--64886075-395d-572b-a9ec-623122f0b8e5
Feed Name: The Hacker News
Check Point analysis found widespread misuse of the open-source Android remote administration tool Rafel RAT—masqueraded as popular apps and delivered via social engineering and malicious PDFs—across ~120 campaigns spanning many countries; the RAT can steal SMS (including 2FA), contacts, location and notifications, manipulate/wipe devices, supports HTTP(S)/Discord C2 and a PHP control panel, and has been used by both APT (DoNot Team / APT-C-35) and criminal operators in ransomware operations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
