Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
We don’t have enough information to confirm how users were directed to the WordPress distribution sites ... but we know that the threat actors behind previous PJobRAT campaigns used a variety of tricks for distribution. These included third-party app stores, compromising legitimate sites to host phishing pages, shortened links to mask final URLs, and fictitious personae to deceive users into clicking on links or downloading the disguised apps.
PJobRAT can steal SMS messages, phone contacts, device and app information, documents, and media files from infected Android devices... PJobRAT uses HTTP to upload data, including device information, SMS, contacts, and files (images, audio/video and documents such as .doc and .pdf files), to the C2 server.
The latest variants of PJobRat have two ways to communicate with their C2 servers. The first is Firebase Cloud Messaging (FCM)... The threat actor used FCM to send commands from a C2 server to the apps and trigger various RAT functions...
10 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android RAT capable of stealing SMS, contacts, device/app info, documents, and media; delivered via fake chat apps; campaign likely aimed at users in Taiwan.
Android remote access trojan disguised as chat or messaging apps. It steals SMS, contacts, device/app information, documents, media files, records audio, uploads files, communicates via Firebase Cloud Messaging and HTTP, and newer variants can execute shell commands for broader device control.
Android spyware/RAT that masquerades as dating and messaging apps, registers infected devices with Firebase-based C2, abuses Android Accessibility Service to steal WhatsApp messages and contacts, collects extensive device and user data, and uploads harvested files and information to remote servers over HTTP/FCM.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.