CraxsRAT is a commercially distributed Android remote access trojan developed and sold by EVLF DEV. Its malware-as-a-service model provides builders that allow operators to customize application branding, requested permissions, features, and command-and-control configuration. Cracked builders have further broadened its availability. CraxsRAT targets Android devices; Windows-based operator tools and maliciously backdoored builders do not establish a Windows-targeting CraxsRAT payload.
The malware provides extensive remote control and surveillance capabilities, including file and SMS management, contact and credential harvesting, keylogging, live screen viewing and recording, camera and microphone access, precise location tracking, and shell command execution. It abuses Android Accessibility Services to access screen content and keystrokes. Its builder produces obfuscated applications and can embed deceptive WebView content to make malicious apps appear functional. Installation options defer permission requests until after initial installation, while anti-removal functionality disrupts attempts to uninstall the application. CraxsRAT also includes mechanisms intended to bypass Google Play Protect.
Observed delivery includes phishing websites distributing malicious Android packages, socially engineered downloads, and counterfeit application updates. Financially motivated campaigns have targeted users in Southeast Asia, including through websites impersonating Malaysian food brands. CraxsRAT has also been used against Ukrainian targets: UNC5812 distributed it through the Civil Defense persona and a decoy application purporting to map military recruiters, while UNC5114 disguised a variant as an update to the Kropyva combat-control application. The Civil Defense operation instructed victims to disable Google Play Protect and manually grant the permissions needed for surveillance and data theft.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“As per our investigation and the official website of CraxsRAT, we can confirm that CraxsRAT only targets Android devices.”
CraxsRAT регулярно всплывает в кампаниях против финансового сектора Юго-Восточной Азии... скачивание APK, кража credentials, вывод средств.
For Android users, the malicious APK file attempts to install a variant of the commercially available Android backdoor CRAXSRAT.
"UNC5114 ... delivered a variant of ... Android malware called CraxsRAT by masquerading it as an update for Kropyva..."
27 distinct techniques documented for this family, organized by ATT&CK tactic.
The ultimate aim of the campaign is to have victims navigate to the UNC5812-controlled "Civil Defense" website, which advertises several different software programs for different operating systems. When installed, these programs result in the download of various commodity malware families.
The ultimate aim of the campaign is to have victims navigate to the UNC5812-controlled "Civil Defense" website, which advertises several different software programs for different operating systems.
UNC5812’s malware delivery operations are conducted both via an actor-controlled Telegram channel @civildefense_com_ua and website hosted at civildefense[.]com.ua. To drive potential victims towards these actor-controlled resources, we assess that UNC5812 is likely purchasing promoted posts in legitimate, established Ukrainian-language Telegram channels.
Technical analysis confirmed: - Remote shell execution
When opened, this version requests the Android REQUEST_INSTALL_PACKAGES permission from the user, which if granted, downloads the CRAXSRAT payload.
CraxsRAT и производные используют Base64 для сокрытия C2-адресов и HTML-кода фишинговых страниц ... Base64/DNGuard обфускация — Obfuscated Files or Information (T1027).
dropper-APK с минимальным набором разрешений вытаскивает из assets/ скрытый payload и ставит его на устройство ... childapp.apk содержит основной RAT.
The Ukrainian-language video instructions then guide victims on how to disable Google Play Protect, the service used to check applications for harmful functionality when they are installed on Android devices, as well as to manually enable all permissions once the malware is successfully installed.
Кейлоггинг (T1056.001), скриншоты (T1113), запись камеры (T1125) и микрофона (T1123).
Оба семейства дают оператору: кейлоггинг, запись экрана и камеры ... Маппинг: запись экрана и скриншоты — Screen Capture (T1113).
Дальнейшая коммуникация через Web Protocols (T1071.001, Command and Control) — оператор шлёт команды, RAT возвращает результаты.
9 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android remote-access trojan that provides remote device control and collects keystrokes, screen/camera/audio recordings, SMS and call data, GPS location, files, device/SIM information, and credentials. It is delivered through phishing APKs, can use an embedded payload/dropper, persists via BOOT_COMPLETED, abuses Accessibility Service, and communicates with C2 over HTTP/HTTPS.
Earlier malware family linked to BTMob.
Android RAT family referenced as a predecessor/successor lineage related to BTMOB.
Android remote access trojan described as the apparent underlying malware family behind EagleSpy V6.0, supporting credential theft, surveillance, remote control, exfiltration, and ransomware-related functionality.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.