The Android Package (APK) file downloaded from the Civil Defense website "CivilDefensse.apk" is a variant of the commercially available Android backdoor CRAXSRAT.
CraxsRAT
CraxsRAT is an Android remote access trojan/backdoor.
Profile source: Mallory opens in a new tabCraxsRAT
Family profile
CraxsRAT is an Android remote access trojan/backdoor. The content describes it as a commercially available/off-the-shelf Android malware family with capabilities including file management, SMS management, contact and credential harvesting, and monitoring of victim location, audio, and keystrokes. Additional reporting in the content associates CraxsRAT or rebranded variants with banking phishing overlays, cryptocurrency wallet credential theft, Telegram bot exfiltration, remote shell execution, camera and microphone access, GPS tracking, ransomware components, DEX packing for antivirus evasion, and hidden update/backdoor mechanisms.
The malware is distributed through social engineering and fake updates. High-confidence examples in the content include suspected Russian actor UNC5812 delivering a CraxsRAT variant via the Civil Defense website and Telegram infrastructure, where the Android APK "CivilDefensse.apk" (MD5: 31cdae71f21e1fad7581b5f305a9d185) was identified as a CraxsRAT variant. Another Android sample (MD5: aab597cdc5bc02f6c9d0d36ddeb7e624) contained the SUNSPINNER decoy app and then downloaded CraxsRAT from h315225216.nichost[.]ru after requesting REQUEST_INSTALL_PACKAGES permission. Victims were instructed in Ukrainian-language videos to disable Google Play Protect and grant extensive Android permissions. The content also states UNC5114 delivered CraxsRAT disguised as an update for the Kropyva combat control system, and more broadly notes CraxsRAT being distributed via fake updates.
Targeting in the content includes Ukrainian military recruits and users of Ukrainian military-related software, as well as broader Android victims in financially motivated campaigns. CraxsRAT is also mentioned in connection with malware bundles alongside NFCGate by February 2025, and reporting cited in the content estimates roughly 180,000 compromised devices in Russia with NFCGate and CraxsRAT installed. The content further notes that EagleSpy V6.0 appears to be a rebranded version of CraxsRAT.
Multiple sources in the content assess BTMOB as an evolution or successor to the CraxsRAT, CypherRAT, and SpySolr families. The actor EVLF / @craxso is associated in the content with the BTMOB ecosystem, and one source links the broader CraxsRAT/CypherRAT/SpySolr lineage to a Syrian threat actor using the alias EVLF. The content also notes medium-confidence evidence that some Lumma affiliates may have used CraxsRAT in parallel with other malware families.
Reported operators
Threat actors
3 named in public reportingMITRE ATT&CK
CraxsRAT in ATT&CK
19 distinct techniquesTechniques
19 techniquesReporting
Research mentioning CraxsRAT
Grandoreiro Malware and BTMOB RAT Campaigns Target Windows and Android Users
BTMOB is believed to be the successor to CraxsRAT, CypherRAT, and SpySolr families.
Technical Analysis of EagleSpy V6.0 (CraxsRAT Rebrand) Distributed Through Odysee and Telegram : r/netsec
I recently investigated an individual operating through Odysee and Telegram who is selling a malicious Android RAT known as EagleSpy V6.0, which appears to be a rebranded version of CraxsRAT.
Six Android Malware Families Target Pix Payments, Banking Apps, and Crypto Wallets
"BTMOB is assessed to be an evolution of CraxsRAT, CypherRAT, and SpySolr families..."
BeatBanker: both banker and miner for Android | Securelist
BTMOB is an Android remote administration tool that evolved from the CraxsRAT, CypherRAT, and SpySolr families.
Coordinated State-Sponsored Cyber Attacks Target Battlefield Management and Defense Supply Chains: Google Links China, Iran, Russia, North Korea
GALLGRAB and CraxsRAT are distributed via WhatsApp and fake updates, respectively.
Suspected Russian hackers deploy CANFAIL malware against Ukraine
UNC5114 spread CraxsRAT disguised as a Kropyva app update.
Google Links China, Iran, Russia, North Korea to Coordinated Defense Sector Cyber Operations
"UNC5114 ... delivered a variant of ... Android malware called CraxsRAT by masquerading it as an update for Kropyva..."
Direct and reverse NFC relay attacks being used to steal money | Kaspersky official blog
"By February 2025, malware bundles combining CraxsRAT and NFCGate emerged..."