CraxsRAT is a commercially available Android remote access trojan and backdoor sold in cybercriminal channels and used in both financially motivated and espionage-linked operations. It is associated with the broader Android malware lineage around SpyNote.C, CypherRAT, and later BTMOB, and has been described as a successor project developed after the commercialization and leak of SpyNote-derived tooling. CraxsRAT has also appeared in rebranded forms, including variants marketed under other names.
CraxsRAT provides extensive remote surveillance and device-control capabilities on Android. Reported functions include file management, SMS management, contact harvesting, credential harvesting, location monitoring, audio monitoring, and keystroke capture. Additional reporting links CraxsRAT-derived or rebranded variants to banking-phishing overlays, remote shell execution, camera and microphone access, GPS tracking, and exfiltration of stolen data. Its abuse of Android permissions and accessibility-related features enables broad post-compromise control and user surveillance.
The malware has been delivered through social-engineering campaigns that trick users into sideloading malicious APKs, including fake application updates and counterfeit app distribution pages. In one notable campaign attributed to UNC5812, a suspected Russian hybrid espionage and influence operation, CraxsRAT was distributed to Android users through a lure aimed at potential Ukrainian military recruits and accompanied by instructions to disable Google Play Protect and grant extensive permissions. Separate reporting also links UNC5114 to delivery of a CraxsRAT variant masquerading as an update for Kropyva, a combat control system used in Ukraine. More broadly, CraxsRAT has been associated with fake-update delivery and with malware bundles combined with NFC-relay tooling.
CraxsRAT has been used against Android users in contexts spanning military-themed targeting, banking abuse, and large-scale criminal operations. It has been discussed in relation to campaigns targeting Ukrainian users, including military-adjacent audiences, and has also been tied to Android fraud ecosystems focused on credential theft, session abuse, and financial theft. Later Android malware families, especially BTMOB, are assessed to have evolved from the CraxsRAT, CypherRAT, and SpySolr ecosystem, indicating its influence on subsequent Android malware-as-a-service offerings.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
For Android users, the malicious APK file attempts to install a variant of the commercially available Android backdoor CRAXSRAT.
"BTMOB is assessed to be an evolution of CraxsRAT, CypherRAT, and SpySolr families..."
"UNC5114 ... delivered a variant of ... Android malware called CraxsRAT by masquerading it as an update for Kropyva..."
21 distinct techniques documented for this family, organized by ATT&CK tactic.
The ultimate aim of the campaign is to have victims navigate to the UNC5812-controlled "Civil Defense" website, which advertises several different software programs for different operating systems. When installed, these programs result in the download of various commodity malware families.
The ultimate aim of the campaign is to have victims navigate to the UNC5812-controlled "Civil Defense" website, which advertises several different software programs for different operating systems.
UNC5812’s malware delivery operations are conducted both via an actor-controlled Telegram channel @civildefense_com_ua and website hosted at civildefense[.]com.ua. To drive potential victims towards these actor-controlled resources, we assess that UNC5812 is likely purchasing promoted posts in legitimate, established Ukrainian-language Telegram channels.
CRAXSRAT provides functionality typical of a standard Android backdoor, to include file management, SMS management, contact and credential harvesting, and a series of monitoring capabilities for location, audio, and keystrokes.
The Ukrainian-language video instructions then guide victims on how to disable Google Play Protect, the service used to check applications for harmful functionality when they are installed on Android devices, as well as to manually enable all permissions once the malware is successfully installed.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android RAT family referenced as a predecessor/successor lineage related to BTMOB.
Android remote access trojan described as the apparent underlying malware family behind EagleSpy V6.0, supporting credential theft, surveillance, remote control, exfiltration, and ransomware-related functionality.
Referenced as a related/precursor RAT family in the lineage leading to BTMOB RAT.
Referenced as an ancestral/related Android RAT family from which BTMOB is assessed to have evolved.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.