CraxsRAT регулярно всплывает в кампаниях против финансового сектора Юго-Восточной Азии... скачивание APK, кража credentials, вывод средств.
CraxsRAT
CraxsRAT is a commercially available Android remote-access trojan and backdoor used in financially motivated mobile-malware activity and espionage-oriented campaigns.
Profile source: Mallory opens in a new tabCraxsRAT
Family profile
CraxsRAT is a commercially available Android remote-access trojan and backdoor used in financially motivated mobile-malware activity and espionage-oriented campaigns. It provides operators with remote device control, file and SMS management, contact and credential harvesting, and monitoring of location, audio, camera output, screen activity, and keystrokes. Variants abuse Android Accessibility Services to capture input and automate user-interface interactions, and may establish persistence by responding to device boot events. CraxsRAT builds commonly obfuscate configuration data and strings and can use multi-stage APK packaging to hinder analysis. The malware has been distributed through malicious APKs masquerading as software updates, including an update for Ukraine's Kropyva combat-control system attributed to UNC5114 activity. It has also appeared in campaigns using fraudulent websites, counterfeit app-store pages, and Telegram-distributed lures, including financial-sector targeting in Southeast Asia. Its commercial builder and malware-as-a-service-style ecosystem enable customized payloads and rapidly changing infrastructure.
Capabilities
- Credential Theft
- Defense Evasion
- Exfiltration
- Keylogging
- Persistence
- Post Exploitation
- Reconnaissance
Reported operators
Threat actors
3 named in public reportingMITRE ATT&CK
CraxsRAT in ATT&CK
27 distinct techniquesTechniques
27 techniquesReporting
Research mentioning CraxsRAT
BTMob Fraud-as-a-Service Platform Uses 1,400 Live Servers to Power Android Device Takeovers
Researchers reported that BTMob is operating as an Android banking malware and fraud-as-a-service platform that lets multiple criminal actors create branded malicious apps and run large-scale device-takeover campaigns. Analysis of leaked source packages and exposed infrastructure linked the operation to roughly 1,400 live servers, including command-and-control nodes, an automated APK-building ecosystem, and backend components used to manage victim infections and operator access. The platform is being spread through fake apps, cloned download pages, and social-engineering lures, including WhatsApp messages and phone calls in Brazil that pressure victims to sideload APKs and grant dangerous permissions. Investigators tied the activity to infrastructure using /yaarsa/ PHP backend paths, HTTP and WebSocket endpoints, a control panel on port 3000 identified by the string "painel de controle elite", and payloads including lnat-tv-pro.apk, BTMob.exe, SolrStarter.exe, and SolrWorker.exe, while also linking the operation to the earlier CraxsRAT and SpySolr malware families.