CraxsRAT is a commercially sold Android remote access trojan and spyware platform that provides broad device-surveillance and remote-control capabilities. It has been described as an off-the-shelf Android backdoor used in criminal operations and as part of a wider ecosystem that also includes CypherRAT, SpySolr, and the later BTMOB platform, which is widely assessed as an evolution or successor of those families. CraxsRAT has also appeared under rebranded names in underground sales channels.
On infected Android devices, CraxsRAT supports file and SMS management, contact harvesting, credential harvesting, location tracking, audio monitoring, and keystroke capture. Reporting also links rebranded variants to banking-phishing overlays, remote shell access, camera and microphone access, GPS tracking, Telegram-based data theft workflows, and hidden update or backdoor mechanisms. These capabilities make it suitable for surveillance, credential theft, and financial fraud, including abuse against banking users.
CraxsRAT is commonly delivered through social engineering rather than app-store distribution. Observed lures include fake application updates, trojanized APKs, counterfeit service or utility apps, and campaigns that persuade victims to sideload packages and grant extensive permissions or disable Android security protections. Documented operations have masqueraded CraxsRAT as updates for Ukrainian military-related software, and a suspected Russian hybrid espionage and influence campaign used a CraxsRAT variant against potential Ukrainian military recruits. Other reporting ties CraxsRAT-derived or associated tooling to financially motivated Android fraud activity and to malware bundles combined with NFC-relay tooling.
The malware is associated with both cybercriminal commercialization and state-linked operational use. It has been marketed as a paid Android malware product, reused by multiple independent actors, and linked in public reporting to the actor using the alias EVLF or @craxso through the broader CraxsRAT/CypherRAT/SpySolr lineage. Its role in the Android threat landscape is notable both as a standalone RAT/backdoor and as a precursor to newer MaaS-style Android fraud platforms.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
For Android users, the malicious APK file attempts to install a variant of the commercially available Android backdoor CRAXSRAT.
"BTMOB is assessed to be an evolution of CraxsRAT, CypherRAT, and SpySolr families..."
"UNC5114 ... delivered a variant of ... Android malware called CraxsRAT by masquerading it as an update for Kropyva..."
21 distinct techniques documented for this family, organized by ATT&CK tactic.
The ultimate aim of the campaign is to have victims navigate to the UNC5812-controlled "Civil Defense" website, which advertises several different software programs for different operating systems. When installed, these programs result in the download of various commodity malware families.
The ultimate aim of the campaign is to have victims navigate to the UNC5812-controlled "Civil Defense" website, which advertises several different software programs for different operating systems.
UNC5812’s malware delivery operations are conducted both via an actor-controlled Telegram channel @civildefense_com_ua and website hosted at civildefense[.]com.ua. To drive potential victims towards these actor-controlled resources, we assess that UNC5812 is likely purchasing promoted posts in legitimate, established Ukrainian-language Telegram channels.
CRAXSRAT provides functionality typical of a standard Android backdoor, to include file management, SMS management, contact and credential harvesting, and a series of monitoring capabilities for location, audio, and keystrokes.
The Ukrainian-language video instructions then guide victims on how to disable Google Play Protect, the service used to check applications for harmful functionality when they are installed on Android devices, as well as to manually enable all permissions once the malware is successfully installed.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Earlier malware family linked to BTMob.
Android RAT family referenced as a predecessor/successor lineage related to BTMOB.
Android remote access trojan described as the apparent underlying malware family behind EagleSpy V6.0, supporting credential theft, surveillance, remote control, exfiltration, and ransomware-related functionality.
Referenced as a related/precursor RAT family in the lineage leading to BTMOB RAT.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.