Oblivion
Oblivion is an Android remote access trojan (RAT) reported by Certo and described as being sold openly on the public web under a subscription model, with pricing cited at $300 per month or $2,200 for lifetime access. It is marketed as easy to use, lowering the technical barrier for cybercriminals and stalkers. The malware commonly infects devices through a fake Google Play update message and includes an APK Builder that can generate trojanized fake apps, including examples masquerading as “Google Services.” Once installed, Oblivion abuses Android Accessibility Service to silently grant itself extensive permissions without user interaction. Reported capabilities include reading private SMS messages to steal banking codes, keylogging to capture passwords and PINs, remotely unlocking a phone after restart, and covert remote control with live screen viewing. During attacker activity, it can display a fake “system updating” animation while the operator navigates apps in the background. Certo reported that its backend infrastructure can support more than 1,000 concurrent victims and that operators can use Tor for anonymity. The malware was reported to target Android 8 through Android 16 and to bypass OEM security layers on major Android brands, specifically including HyperOS, Xiaomi MIUI, OPPO ColorOS, Honor MagicOS, Samsung One UI, and OnePlus OxygenOS. The seller also claimed it had been tested for four months to evade behavioral detection and remain hidden from antivirus software.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Techniques & procedures
4 distinct techniques documented for this family, organized by ATT&CK tactic.
Execution
1 technique
Execution
Stealth
1 technique
Stealth
Credential Access
1 technique
Credential Access
Collection
1 technique
Collection
Recent activity
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Commercial Android RAT (MaaS) claiming automated permission granting/bypass across multiple OEM Android variants; emphasizes hidden remote control, persistence, and a point-and-click builder to lower operator skill requirements.
Android remote access trojan (RAT) being sold on underground forums.
Android remote access trojan sold as a subscription service that abuses Accessibility Service to silently gain extensive permissions, enabling SMS theft (e.g., bank codes/2FA), keylogging of passwords/PINs, remote device control including screen viewing in a hidden mode, and the ability to remotely unlock the phone after restart. Includes tooling (APK builder) to generate convincing fake apps (e.g., Google Services) to aid delivery and evasion.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.