CraxsRAT Mobile Malware

General News

Summary

Cybersecurity experts have reportedly uncovered the true identity of the individual responsible for developing the Remote Access Trojans (RATs) known as CypherRAT and CraxsRAT. Operating under the online alias EVLF DEV and based in Syria for the last eight years, this threat actor is believed to have generated more than $75,000 by distributing these two RATs to various threatening entities. CraxsRAT generates intricately obfuscated packages, granting malicious actors the flexibility to tailor their content based on the intended type of attack, including WebView page injections. This Trojan leverages the Android Accessibility Services to gain a variety of features, including keylogging, touchscreen manipulation, and automatic option selection. This RAT can initiate infection chains either by downloading and executing payloads itself or by deceiving victims into doing so through forcefully opened malicious websites.

Classifications

industries
Entertainment
applications
Customer Service & Support

AskAI Classifications

Labels
Cybersecurity Software Anti-Malware Software SaaS Security

Linked Companies

EnigmaSoft
$1M to $5M