RatOn is a threat actor and associated malware operation linked to Android financial fraud activity centered on a custom mobile trojan that combines remote access, overlay abuse, automated transfer capabilities, and NFC-relay enablement through NFSkate. The operation has targeted Czech- and Slovak-speaking victims and shows detailed knowledge of regional banking workflows, particularly the George Česko banking application, while also pursuing cryptocurrency theft through wallet compromise. The Android malware used by this actor appears to have been developed from scratch and deployed through a multi-stage infection chain involving a dropper, a second-stage RAT payload, and in some cases a third-stage NFSkate component. The malware abuses Accessibility Services, Device Administrator privileges, and additional Android permissions to achieve device takeover, monitor foreground activity, automate user-interface interaction, approve permission prompts, lock the device, and display custom overlays. It supports both hosted and inline HTML overlays, including ransom-style screens used to pressure victims into opening targeted applications so the operators can capture authentication material. RatOn supports automated fraudulent transfers by driving banking-app workflows through Accessibility-based interaction, including checking and modifying transaction limits and confirming payments with previously intercepted PINs. It also targets cryptocurrency wallet applications such as MetaMask, Trust Wallet, Blockchain.com, and Phantom, launching them, unlocking them with stolen credentials or PINs, navigating security settings, and extracting wallet recovery phrases. The malware includes keylogging and extensive remote-control functions, and can deploy or invoke NFSkate to support NFC relay attacks against payment cards. The activity is assessed as an evolution of NFSkate operations in which the operators significantly expanded capability by adding remote access and automated transfer functionality. Known aliases associated with the actor naming include RAT-ON, raton, and rat_on_threat_actor_group. Separately, the name RatonRAT has also been used for an unrelated .NET malware-as-a-service remote access trojan sold by an operator using aliases including silly, sillycs, sillyok, and sillyisafed. That Windows malware supports a broad command set including credential theft, keylogging, persistence, ransomware, DDoS, SOCKS5 proxying, HVNC, and on-host code compilation. Despite the similar naming, the Android RatOn banking-fraud operation and the .NET RatonRAT MaaS offering are distinct malware efforts.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
23 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malware-as-a-service operation selling a .NET RAT with remote access, credential theft, crypto clipper, ransomware, HVNC, DDoS, SOCKS5 proxy, plugin SDK, and on-victim code compilation capabilities through tiered pricing and public distribution channels.
Threat actor group behind the RatOn Android banking trojan, extending NFSkate capabilities with remote access, ATS fraud, ransomware-style overlays, and crypto wallet compromise.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.