Skip to content

CraxsRAT

CraxsRAT is a commercially available Android remote-access trojan and backdoor used in financially motivated mobile-malware activity and espionage-oriented campaigns.

Profile source: Mallory opens in a new tab

CraxsRAT

Family profile

CraxsRAT is a commercially available Android remote-access trojan and backdoor used in financially motivated mobile-malware activity and espionage-oriented campaigns. It provides operators with remote device control, file and SMS management, contact and credential harvesting, and monitoring of location, audio, camera output, screen activity, and keystrokes. Variants abuse Android Accessibility Services to capture input and automate user-interface interactions, and may establish persistence by responding to device boot events. CraxsRAT builds commonly obfuscate configuration data and strings and can use multi-stage APK packaging to hinder analysis. The malware has been distributed through malicious APKs masquerading as software updates, including an update for Ukraine's Kropyva combat-control system attributed to UNC5114 activity. It has also appeared in campaigns using fraudulent websites, counterfeit app-store pages, and Telegram-distributed lures, including financial-sector targeting in Southeast Asia. Its commercial builder and malware-as-a-service-style ecosystem enable customized payloads and rapidly changing infrastructure.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Keylogging
  • Persistence
  • Post Exploitation
  • Reconnaissance

Reported operators

Threat actors

3 named in public reporting
EVLF

CraxsRAT регулярно всплывает в кампаниях против финансового сектора Юго-Восточной Азии... скачивание APK, кража credentials, вывод средств.

UNC5812

For Android users, the malicious APK file attempts to install a variant of the commercially available Android backdoor CRAXSRAT.

UNC5114

"UNC5114 ... delivered a variant of ... Android malware called CraxsRAT by masquerading it as an update for Kropyva..."

MITRE ATT&CK

CraxsRAT in ATT&CK

27 distinct techniques

Reporting

Research mentioning CraxsRAT

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.