216.73.216.6

The Rise of RatOn: From NFC heists to remote control and ATS

· Published 09/09/2025 21:06 · Modified 09/09/2025 22:06

Export JSON

Essential information

Published
09/09/2025 21:06
Modified
09/09/2025 22:06
Tags
2025-09-09 android ats banking trojan cryptocurrency nfc relay nfskate overlay attacks rat raton
Related entities
23 observables, 1 intrusion sets (apt), 3 techniques (mitre), 2 others

Description

A new named has emerged, combining attacks with remote access and automated transfer capabilities. Discovered by analysts monitoring the threat group, targets wallets and banking applications, particularly in the Czech Republic and Slovakia. The malware is distributed through adult-themed websites and employs a multi-stage infection process. features , automated money transfers, and wallet takeovers. It demonstrates sophisticated capabilities, including screen casting, PIN interception, and extensive bot commands. The trojan's evolution from a basic tool to a complex with functionality makes it a significant threat in the mobile malware landscape.

External references