EVLF, also known as EVLF DEV and the online handle @craxso, is a Syria-based malware-as-a-service developer and seller associated with Android remote-access trojans. EVLF developed and commercialized CypherRAT and CraxsRAT and subsequently advertised BTMOB, an Android RAT linked to the evolution of those families. The operation is financially motivated, offering malware builders, subscriptions, lifetime licenses, and source-code packages, with cryptocurrency accepted for payment. More than 100 distinct buyers reportedly purchased lifetime licenses for EVLF’s RATs over a three-year period. CraxsRAT provides remote device control, keylogging, screen recording and live viewing, location tracking, access to contacts and communications, camera and microphone surveillance, and shell-command execution. It abuses Android accessibility services to capture input and control devices. Its builder supports customizable application branding, permissions, and deceptive WebView content. Obfuscation, Google Play Protect bypass features, delayed permission requests, and interference with uninstallation support evasion and continued access. BTMOB additionally supports credential theft through HTML injections, device unlocking, and PIN capture. These tools enable third-party criminal operators to conduct surveillance, data theft, and financial fraud. CraxsRAT campaigns have used Malaysian-brand phishing lures, while BTMOB has been deployed against Brazilian mobile users. These deployments do not establish that EVLF personally operated the campaigns. Cracked and leaked builders and source code have broadened access to the malware. CraxsRAT itself targets Android; Windows malware and ransomware found in some redistributed builders are separate malicious additions rather than established capabilities of the Android RAT.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 malware families attributed to this actor across reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Предположительно связан с разработкой CraxsRAT; атрибуция в источнике прямо отмечена как неподтверждённая и требующая независимой верификации.
Advertises and sells the BTMOB Android RAT under a malware-as-a-service model, including subscriptions, lifetime licenses, and full server source code.
Syrian-linked threat actor associated (via tooling lineage) with Android RAT families (CraxsRAT/CypherRAT/SpySolr) and the BTMOB RAT evolution used for persistent remote control and surveillance of Android devices; indirectly relevant here because BeatBanker campaigns have been observed dropping BTMOB as a payload.
A malware-as-a-service operator attributed by the report to an individual operating from Syria. EVLF develops and sells CypherRAT and CraxsRAT, reportedly purchased by more than 100 distinct threat actors over three years. CraxsRAT is an Android remote-access trojan with surveillance, data-access, command-execution, and anti-uninstallation capabilities. EVLF markets it through a surface-web shop and accepts cryptocurrency payments. The report distinguishes the Android malware from Windows-based builders whose unofficial cracked copies may contain unrelated backdoors; it does not establish that EVLF planted those backdoors.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.