CraxsRAT is an Android remote access trojan/backdoor. The content describes it as a commercially available/off-the-shelf Android malware family with capabilities including file management, SMS management, contact and credential harvesting, and monitoring of victim location, audio, and keystrokes. Additional reporting in the content associates CraxsRAT or rebranded variants with banking phishing overlays, cryptocurrency wallet credential theft, Telegram bot exfiltration, remote shell execution, camera and microphone access, GPS tracking, ransomware components, DEX packing for antivirus evasion, and hidden update/backdoor mechanisms.
The malware is distributed through social engineering and fake updates. High-confidence examples in the content include suspected Russian actor UNC5812 delivering a CraxsRAT variant via the Civil Defense website and Telegram infrastructure, where the Android APK "CivilDefensse.apk" (MD5: 31cdae71f21e1fad7581b5f305a9d185) was identified as a CraxsRAT variant. Another Android sample (MD5: aab597cdc5bc02f6c9d0d36ddeb7e624) contained the SUNSPINNER decoy app and then downloaded CraxsRAT from h315225216.nichost[.]ru after requesting REQUEST_INSTALL_PACKAGES permission. Victims were instructed in Ukrainian-language videos to disable Google Play Protect and grant extensive Android permissions. The content also states UNC5114 delivered CraxsRAT disguised as an update for the Kropyva combat control system, and more broadly notes CraxsRAT being distributed via fake updates.
Targeting in the content includes Ukrainian military recruits and users of Ukrainian military-related software, as well as broader Android victims in financially motivated campaigns. CraxsRAT is also mentioned in connection with malware bundles alongside NFCGate by February 2025, and reporting cited in the content estimates roughly 180,000 compromised devices in Russia with NFCGate and CraxsRAT installed. The content further notes that EagleSpy V6.0 appears to be a rebranded version of CraxsRAT.
Multiple sources in the content assess BTMOB as an evolution or successor to the CraxsRAT, CypherRAT, and SpySolr families. The actor EVLF / @craxso is associated in the content with the BTMOB ecosystem, and one source links the broader CraxsRAT/CypherRAT/SpySolr lineage to a Syrian threat actor using the alias EVLF. The content also notes medium-confidence evidence that some Lumma affiliates may have used CraxsRAT in parallel with other malware families.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The Android Package (APK) file downloaded from the Civil Defense website "CivilDefensse.apk" is a variant of the commercially available Android backdoor CRAXSRAT.
"BTMOB is assessed to be an evolution of CraxsRAT, CypherRAT, and SpySolr families..."
"UNC5114 ... delivered a variant of ... Android malware called CraxsRAT by masquerading it as an update for Kropyva..."
19 distinct techniques documented for this family, organized by ATT&CK tactic.
CRAXSRAT provides functionality typical of a standard Android backdoor, to include file management, SMS management, contact and credential harvesting, and a series of monitoring capabilities for location, audio, and keystrokes.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android RAT family referenced as a predecessor/successor lineage related to BTMOB.
Android remote access trojan described as the apparent underlying malware family behind EagleSpy V6.0, supporting credential theft, surveillance, remote control, exfiltration, and ransomware-related functionality.
Referenced as a related/precursor RAT family in the lineage leading to BTMOB RAT.
Referenced as an ancestral/related Android RAT family from which BTMOB is assessed to have evolved.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.