Skip to main content
Mallory
MalwareRansomwareUsed by 2 actors

CraxsRAT

CraxsRAT is an Android remote access trojan (RAT) used for device compromise, surveillance, credential theft, and financial fraud. The provided content describes it as a highly sophisticated Android RAT associated with bypassing 2FA and hijacking mobile banking sessions, and as part of an Android malware ecosystem that later evolved into BTMOB. Multiple sources in the content assess BTMOB as a successor or evolution of the CraxsRAT, CypherRAT, and SpySolr families.

Observed delivery in the content includes fake app updates and social engineering. Google Threat Intelligence reporting cited in the content states UNC5114 delivered a variant of CraxsRAT by masquerading it as an update for Kropyva, a combat control system used in Ukraine. Other references note CraxsRAT being distributed via fake updates, and malware bundles combining CraxsRAT with NFCGate emerging by February 2025. The content also states that EagleSpy V6.0 appears to be a rebranded version of CraxsRAT and that this rebranded malware was sold via Odysee and Telegram.

Capabilities attributed in the content include remote administration and banking-focused abuse. The EagleSpy/CraxsRAT-linked analysis describes banking phishing overlays, theft of cryptocurrency wallet credentials, Telegram bot exfiltration, remote shell execution, keylogging, camera and microphone access, GPS tracking, ransomware components, DEX packers for antivirus evasion, and hidden update/backdoor mechanisms. The content also references CraxsRAT in the context of bypassing 2FA and hijacking banking sessions. Separately, the content notes estimated large-scale infections in Russia where compromised devices had both NFCGate and CraxsRAT installed.

The malware is linked in the content to actors and ecosystems associated with Android MaaS/RAT activity. Kaspersky/ESET reporting summarized in the content ties the broader CraxsRAT lineage to the Syrian threat actor alias EVLF/@craxso through its evolution into BTMOB. In state-linked operations, the content specifically associates delivery of CraxsRAT with UNC5114 targeting Ukrainian military users through a fake Kropyva update.

High-confidence targeting reflected in the content includes Android users involved in banking fraud scenarios, victims of fake updates, and Ukrainian military or defense-related users through Kropyva-themed lures. Related indicators and contextual artifacts mentioned in the content include the Odysee channel https://odysee.com/@justicerat:e and Telegram account @JustIcedevs used to market EagleSpy V6.0, which was assessed as a rebrand of CraxsRAT.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
EVLF

"BTMOB is assessed to be an evolution of CraxsRAT, CypherRAT, and SpySolr families..."

via the hacker newsthehackernews.com
UNC5114

"UNC5114 ... delivered a variant of ... Android malware called CraxsRAT by masquerading it as an update for Kropyva..."

via the hacker newsthehackernews.com
MITRE ATT&CK

Techniques & procedures

12 distinct techniques documented for this family, organized by ATT&CK tactic.

Execution

1 technique
T1059Command and Scripting InterpreterEvidence1

Technical analysis confirmed: - Remote shell execution

Stealth

3 techniques
T1027.002Software PackingEvidence1

Technical analysis confirmed: - DEX packers for AV evasion

T1036MasqueradingEvidence2

“UNC5114 spread CraxsRAT disguised as a Kropyva app update.”

T1564.003Hidden WindowEvidence1

Technical analysis confirmed: - Hidden update/backdoor mechanisms

Credential Access

3 techniques
T1056.001KeyloggingEvidence1

Technical analysis confirmed: - Keylogging

T1056.004Credential API HookingEvidence1

Technical analysis confirmed: - Banking phishing overlays

T1555Credentials from Password StoresEvidence1

Technical analysis confirmed: - Crypto wallet credential theft

Collection

4 techniques
T1056.001KeyloggingEvidence1

Technical analysis confirmed: - Keylogging

T1056.004Credential API HookingEvidence1

Technical analysis confirmed: - Banking phishing overlays

T1123Audio CaptureEvidence1

Technical analysis confirmed: - Camera/microphone access

T1125Video CaptureEvidence1

Technical analysis confirmed: - Camera/microphone access

Command and Control

1 technique
T1219Remote Access ToolsEvidence1

"[SEARCH] 'craxs rat v8'... Hunting for CraxsRAT... used for bypassing 2FA and hijacking mobile banking sessions."

Exfiltration

1 technique
T1567Exfiltration Over Web ServiceEvidence1

Technical analysis confirmed: - Telegram bot exfiltration

Impact

1 technique
T1486Data Encrypted for ImpactEvidence1

Technical analysis confirmed: - Ransomware components

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution2

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping12

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.