216.73.216.36

Rat King: How the Android Trojan CraxsRAT Steals User Data

· Published 31/10/2024 08:23 · Modified 31/10/2024 20:00

Export JSON

Essential information

Published
31/10/2024 08:23
Modified
31/10/2024 20:00
Tags
2024-10-31 android craxsrat data theft espionage financial fraud remote access social engineering trojan
Related entities
14 techniques (mitre), 1 malware, 5 others

Description

, an , has been targeting Russian and Belarusian users since summer 2024. It masquerades as legitimate apps like government services, antivirus software, and telecom operators. The malware spreads through tactics, prompting users to download malicious APK files via messaging apps. has extensive capabilities, including remote device control, data exfiltration, call and SMS interception, keylogging, and camera/microphone access. It uses various techniques to evade detection and removal. The is believed to be used by both financially motivated groups and those engaged in cyber . Over 140 unique samples have been identified, with the threat continuing to evolve and adapt to maintain its effectiveness.

External references