Fantasy Hub is an Android remote access trojan (RAT) sold as a malware-as-a-service (MaaS) offering on Russian-language cybercrime channels. Zimperium zLabs researchers described it as a Russian-market MaaS operation promoted via Telegram with subscription tiers, videos, documentation, and chatbot-based access that lowers the barrier for less-skilled operators. The malware is designed for espionage, data theft, and full remote control of infected Android devices.
Reported capabilities include interception of SMS messages, access to contacts, call logs, images, and videos, and manipulation of incoming notifications, including intercepting, replying to, and deleting them. Additional reported functions include call recording, activation of the camera and microphone, bulk data theft, and live audio/video streaming over encrypted WebRTC channels. Fantasy Hub also includes operator-facing command-and-control functionality that provides detailed device information and supports remote monitoring and operation of compromised phones. The dashboard reportedly displays device details such as model, SIM slot identifiers, and subscription time remaining.
Fantasy Hub is associated with credential theft against financial institutions through phishing overlays and fake login windows impersonating Russian banks including Alfa-Bank, PSB, Tbank, and Sber. These overlays are used to steal usernames, passwords, card numbers, PINs, and two-factor authentication codes. The malware’s interception of SMS and abuse of Android roles/components further supports real-time theft of banking credentials and authentication codes, posing a significant risk to mobile banking users and other users of sensitive applications.
The MaaS ecosystem around Fantasy Hub includes a Telegram bot with a dropper function that allows buyers to upload an APK and receive a version appended with the Fantasy Hub dropper. The operator also provides tutorials and instructions for disguising payloads as legitimate apps, using fake icons and reviews, and hosting fraudulent Google Play-style phishing pages; one observed lure impersonated Telegram. Technically, reported samples contain a native dropper in a module named metamask_loader that decrypts an encrypted file named metadata.dat at runtime using a custom XOR-based routine and gzip decompression, a design intended to reduce static detection and hinder antivirus and sandbox analysis.
High-confidence associations in the provided content are limited to Russian-language cybercrime distribution channels and Russian-bank-themed credential theft; no specific threat actor attribution beyond that is confirmed.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
A standout feature of Fantasy Hub is its phishing overlay system that targets customers of major Russian banks including Alfa-Bank, PSB, Tbank, and Sber. The spyware can spawn fake login screens directly over legitimate apps, tricking users into entering credentials, card numbers, and PINs.
A native dropper embedded within a module named metamask_loader decrypts an encrypted file (metadata.dat) at runtime using a custom XOR-based routine and gzip decompression.
Attackers target financial institutions by displaying fake login windows for banks like Alfa, PSB, Tbank, and Sber to steal credentials.
The spyware can spawn fake login screens directly over legitimate apps, tricking users into entering credentials, card numbers, and PINs.
These capabilities include the exfiltration of SMS messages, contacts, call logs, and bulk theft of images and videos.
Attackers target financial institutions by displaying fake login windows for banks like Alfa, PSB, Tbank, and Sber to steal credentials.
The spyware can spawn fake login screens directly over legitimate apps, tricking users into entering credentials, card numbers, and PINs.
Fantasy Hub, a Russian malware-as-a-service (MaaS) Android remote access trojan (RAT) that allows attackers to spy, steal data, and control devices through Telegram.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Near-identical Russian-market Android rental malware kit mentioned for comparison with RedWing.
Android remote access trojan offered as malware-as-a-service that enables attackers to control infected devices, intercept SMS messages, access contacts, call logs, images and videos, manipulate notifications, and steal banking credentials via fake login windows.
Android malware sold as a MaaS offering that provides full device control, data exfiltration, SMS interception, call recording, camera activation, live audio/video streaming via WebRTC, notification interception, and phishing overlays targeting banking credentials.
Named in the content as a malware-related tag in a mobile security and malware issue covering Android topics.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.