Skip to content
Malware family

CraxsRAT

CraxsRAT is an Android remote access trojan/backdoor.

Profile source: Mallory opens in a new tab

CraxsRAT

Family profile

CraxsRAT is an Android remote access trojan/backdoor. The content describes it as a commercially available/off-the-shelf Android malware family with capabilities including file management, SMS management, contact and credential harvesting, and monitoring of victim location, audio, and keystrokes. Additional reporting in the content associates CraxsRAT or rebranded variants with banking phishing overlays, cryptocurrency wallet credential theft, Telegram bot exfiltration, remote shell execution, camera and microphone access, GPS tracking, ransomware components, DEX packing for antivirus evasion, and hidden update/backdoor mechanisms.

The malware is distributed through social engineering and fake updates. High-confidence examples in the content include suspected Russian actor UNC5812 delivering a CraxsRAT variant via the Civil Defense website and Telegram infrastructure, where the Android APK "CivilDefensse.apk" (MD5: 31cdae71f21e1fad7581b5f305a9d185) was identified as a CraxsRAT variant. Another Android sample (MD5: aab597cdc5bc02f6c9d0d36ddeb7e624) contained the SUNSPINNER decoy app and then downloaded CraxsRAT from h315225216.nichost[.]ru after requesting REQUEST_INSTALL_PACKAGES permission. Victims were instructed in Ukrainian-language videos to disable Google Play Protect and grant extensive Android permissions. The content also states UNC5114 delivered CraxsRAT disguised as an update for the Kropyva combat control system, and more broadly notes CraxsRAT being distributed via fake updates.

Targeting in the content includes Ukrainian military recruits and users of Ukrainian military-related software, as well as broader Android victims in financially motivated campaigns. CraxsRAT is also mentioned in connection with malware bundles alongside NFCGate by February 2025, and reporting cited in the content estimates roughly 180,000 compromised devices in Russia with NFCGate and CraxsRAT installed. The content further notes that EagleSpy V6.0 appears to be a rebranded version of CraxsRAT.

Multiple sources in the content assess BTMOB as an evolution or successor to the CraxsRAT, CypherRAT, and SpySolr families. The actor EVLF / @craxso is associated in the content with the BTMOB ecosystem, and one source links the broader CraxsRAT/CypherRAT/SpySolr lineage to a Syrian threat actor using the alias EVLF. The content also notes medium-confidence evidence that some Lumma affiliates may have used CraxsRAT in parallel with other malware families.

Reported operators

Threat actors

3 named in public reporting
UNC5812

The Android Package (APK) file downloaded from the Civil Defense website "CivilDefensse.apk" is a variant of the commercially available Android backdoor CRAXSRAT.

EVLF

"BTMOB is assessed to be an evolution of CraxsRAT, CypherRAT, and SpySolr families..."

UNC5114

"UNC5114 ... delivered a variant of ... Android malware called CraxsRAT by masquerading it as an update for Kropyva..."

MITRE ATT&CK

CraxsRAT in ATT&CK

19 distinct techniques

Reporting

Research mentioning CraxsRAT

May 27
The Hacker News

Grandoreiro Malware and BTMOB RAT Campaigns Target Windows and Android Users

BTMOB is believed to be the successor to CraxsRAT, CypherRAT, and SpySolr families.

May 9
Reddit Netsec

Technical Analysis of EagleSpy V6.0 (CraxsRAT Rebrand) Distributed Through Odysee and Telegram : r/netsec

I recently investigated an individual operating through Odysee and Telegram who is selling a malicious Android RAT known as EagleSpy V6.0, which appears to be a rebranded version of CraxsRAT.

Mar 12
The Hacker News

Six Android Malware Families Target Pix Payments, Banking Apps, and Crypto Wallets

"BTMOB is assessed to be an evolution of CraxsRAT, CypherRAT, and SpySolr families..."

Mar 10
Securelist

BeatBanker: both banker and miner for Android | Securelist

BTMOB is an Android remote administration tool that evolved from the CraxsRAT, CypherRAT, and SpySolr families.

Feb 15
Rescana

Coordinated State-Sponsored Cyber Attacks Target Battlefield Management and Defense Supply Chains: Google Links China, Iran, Russia, North Korea

GALLGRAB and CraxsRAT are distributed via WhatsApp and fake updates, respectively.

Feb 14
Security Affairs

Suspected Russian hackers deploy CANFAIL malware against Ukraine

UNC5114 spread CraxsRAT disguised as a Kropyva app update.

Feb 13
The Hacker News

Google Links China, Iran, Russia, North Korea to Coordinated Defense Sector Cyber Operations

"UNC5114 ... delivered a variant of ... Android malware called CraxsRAT by masquerading it as an update for Kropyva..."

Jan 13
Kaspersky

Direct and reverse NFC relay attacks being used to steal money | Kaspersky official blog

"By February 2025, malware bundles combining CraxsRAT and NFCGate emerged..."

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.