RatOn is an Android banking trojan and remote access malware family that combines device takeover, overlay-based fraud, automated transfer system functionality, and NFC relay enablement. It has been associated with activity linked to the NFSkate ecosystem and appears to have been developed as a multi-stage Android campaign targeting primarily Czech- and Slovak-speaking victims, with a strong focus on financial theft from both banking applications and cryptocurrency wallets.
RatOn is delivered through malicious dropper applications masquerading as third-party software, including adult-themed lures impersonating modified social-media apps. After installation, the malware requests Accessibility Services and device administration privileges, then abuses Accessibility to grant itself further permissions and to automate interaction with targeted applications. Its command set supports extensive remote control of the infected device, including screen monitoring, text entry, keypad interaction, SMS-related actions, clipboard manipulation, device locking, and other post-compromise operations.
A defining feature of RatOn is its support for automated banking fraud. It can interact with targeted banking applications through Accessibility-driven UI automation, including initiating transfers, checking or modifying transaction limits, and entering previously captured authentication data to confirm fraudulent payments. RatOn also supports overlay attacks using hosted or inline HTML content, including ransom-style lock-screen pages that can coerce victims into opening sensitive applications and disclosing unlock credentials.
RatOn also targets cryptocurrency wallets such as MetaMask, Trust Wallet, Blockchain.com, and Phantom. It can launch these apps, unlock them using stolen credentials, navigate wallet interfaces, expose recovery phrases, and capture sensitive wallet data for exfiltration. Reported functionality includes keylogging of revealed wallet recovery information and multilingual support for wallet-related interactions.
The malware can additionally deploy or invoke NFSkate as a further-stage payload to conduct NFC relay attacks against payment cards. This combination of RAT control, ATS banking fraud, wallet theft, and NFC relay capability makes RatOn notable among Android financial malware families. Available reporting characterizes it as a newly developed family rather than a variant of previously known codebases.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
That’s why the discovery of the new trojan RatOn by ThreatFabric MTI analysts is particularly noteworthy. RatOn merges traditional overlay attacks with automatic money transfers and NFC relay functionality—making it a uniquely powerful threat.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
The JavaScript code with Install button which will call function exported by Dropper... The page on that URL consist of the code with the button that will trigger exported from the payload function ask Accessibility
The dropper, which is designed as a third party software installer, will request the permission from the victim to install applications from third party sources.
What separated this sample from previous ones was the fact that it was not just a standalone APK file... The installApk function will create an install session which will open the second stage payload APK file from the assets of the dropper and install that application into the system.
After the successful installation, the second stage payload will be executed, and it will immediately ask for two main permissions that are crucial for performing fraud of the device: Accessibility service access and Device Admin privilege.
disable_keyguard Force victim to unlock the device using PIN/Pattern or password instead of using biometrical authentication. expire_password Set current device unlock pin/pattern/password to expired. Victim will have to immediately change it. So, it would be intercepted by attacker.
disable_keyguard Force victim to unlock the device using PIN/Pattern or password instead of using biometrical authentication. expire_password Set current device unlock pin/pattern/password to expired. Victim will have to immediately change it. So, it would be intercepted by attacker.
We believe that such a note could be used in two ways: force the victim to open the cryptocurrency apps so the unlocking PIN will be captured by trojan... The keylogger component will record revealed data and will send it to control server.
The keylogger component will record revealed data and will send it to control server.
disable_keyguard Force victim to unlock the device using PIN/Pattern or password instead of using biometrical authentication. expire_password Set current device unlock pin/pattern/password to expired. Victim will have to immediately change it. So, it would be intercepted by attacker.
We believe that such a note could be used in two ways: force the victim to open the cryptocurrency apps so the unlocking PIN will be captured by trojan... The keylogger component will record revealed data and will send it to control server.
23 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Threat/campaign codename associated with dropper apps that impersonate adult-themed TikTok variants to deploy NGate for NFC relay attacks.
Android malware evolving into a RAT with NFC relay and Automated Transfer System (ATS) capabilities for banking fraud.
Android trojan combining remote device control with NFC relay; capabilities described include screen capture, clipboard manipulation, SMS sending, and theft of information from crypto wallets and banking apps to enable payment/ATM fraud.
Android malware combining remote access trojan (RAT) capabilities with NFC relay attacks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.