For Android users, the malicious APK file attempts to install a variant of the commercially available Android backdoor CRAXSRAT.
CraxsRAT
CraxsRAT is a commercially sold Android remote access trojan and spyware platform that provides broad device-surveillance and remote-control capabilities.
Profile source: Mallory opens in a new tabCraxsRAT
Family profile
CraxsRAT is a commercially sold Android remote access trojan and spyware platform that provides broad device-surveillance and remote-control capabilities. It has been described as an off-the-shelf Android backdoor used in criminal operations and as part of a wider ecosystem that also includes CypherRAT, SpySolr, and the later BTMOB platform, which is widely assessed as an evolution or successor of those families. CraxsRAT has also appeared under rebranded names in underground sales channels.
On infected Android devices, CraxsRAT supports file and SMS management, contact harvesting, credential harvesting, location tracking, audio monitoring, and keystroke capture. Reporting also links rebranded variants to banking-phishing overlays, remote shell access, camera and microphone access, GPS tracking, Telegram-based data theft workflows, and hidden update or backdoor mechanisms. These capabilities make it suitable for surveillance, credential theft, and financial fraud, including abuse against banking users.
CraxsRAT is commonly delivered through social engineering rather than app-store distribution. Observed lures include fake application updates, trojanized APKs, counterfeit service or utility apps, and campaigns that persuade victims to sideload packages and grant extensive permissions or disable Android security protections. Documented operations have masqueraded CraxsRAT as updates for Ukrainian military-related software, and a suspected Russian hybrid espionage and influence campaign used a CraxsRAT variant against potential Ukrainian military recruits. Other reporting ties CraxsRAT-derived or associated tooling to financially motivated Android fraud activity and to malware bundles combined with NFC-relay tooling.
The malware is associated with both cybercriminal commercialization and state-linked operational use. It has been marketed as a paid Android malware product, reused by multiple independent actors, and linked in public reporting to the actor using the alias EVLF or @craxso through the broader CraxsRAT/CypherRAT/SpySolr lineage. Its role in the Android threat landscape is notable both as a standalone RAT/backdoor and as a precursor to newer MaaS-style Android fraud platforms.
Capabilities
- Credential Theft
- Defense Evasion
- Exfiltration
- Keylogging
- Post Exploitation
Reported operators
Threat actors
3 named in public reportingMITRE ATT&CK
CraxsRAT in ATT&CK
21 distinct techniquesTechniques
21 techniquesReporting
Research mentioning CraxsRAT
BTMob Fraud-as-a-Service Platform Uses 1,400 Live Servers to Power Android Device Takeovers
Researchers reported that BTMob is operating as an Android banking malware and fraud-as-a-service platform that lets multiple criminal actors create branded malicious apps and run large-scale device-takeover campaigns. Analysis of leaked source packages and exposed infrastructure linked the operation to roughly 1,400 live servers, including command-and-control nodes, an automated APK-building ecosystem, and backend components used to manage victim infections and operator access. The platform is being spread through fake apps, cloned download pages, and social-engineering lures, including WhatsApp messages and phone calls in Brazil that pressure victims to sideload APKs and grant dangerous permissions. Investigators tied the activity to infrastructure using /yaarsa/ PHP backend paths, HTTP and WebSocket endpoints, a control panel on port 3000 identified by the string "painel de controle elite", and payloads including lnat-tv-pro.apk, BTMob.exe, SolrStarter.exe, and SolrWorker.exe, while also linking the operation to the earlier CraxsRAT and SpySolr malware families.