Cyber Android RAT is an Android remote access Trojan advertised on criminal hacking forums as a commercially sold surveillance and theft tool. Mobile security firm Certo reported that it is supported by a command-and-control platform called Cyber Nebula Core and is marketed for approximately $499 per month or $2,500 for lifetime access. Reported capabilities include covert remote control via hidden VNC, live microphone streaming, real-time access to both front and rear cameras, keylogging, notification interception, and remote file management including upload, download, and deletion with access to internal storage and SD cards. The malware also includes a dedicated module to extract historical WhatsApp messages and can intercept notifications from apps including WhatsApp, Gmail, and banking applications. A notable feature is automated cryptocurrency theft targeting Android wallet applications such as MetaMask and Binance through programmatic in-app navigation and fund transfer, with Certo reporting that this does not rely on overlay attacks. Certo observed the hidden VNC module operating on a Samsung device without obvious signs of malicious activity to the victim. The seller claims compatibility across all Android versions and devices. No region-specific targeting was reported, and researchers assessed it is likely intended for global deployment. Associated threat actor attribution is not provided in the content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
Cyber Android RAT also has the ability to "download, upload and delete files" remotely
Keylogger functions run simultaneously alongside both monitoring and crypto modules, capturing keystrokes to gain access to encrypted messaging apps like Telegram or WhatsApp.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android remote access trojan marketed on criminal forums that enables full device surveillance and control, including hidden VNC access, microphone and camera streaming, keylogging, WhatsApp history extraction, notification interception, file management, and automated theft from crypto wallets such as MetaMask and Binance.
Android remote access trojan marketed on criminal forums that enables full device control, hidden VNC access, live surveillance, keylogging, WhatsApp history extraction, notification interception, file management, and automated theft from cryptocurrency wallets including MetaMask and Binance.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.