Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Malware

RecruitRat

RecruitRat is an Android banking trojan/RAT family identified by Zimperium zLabs as one of four related campaigns alongside SaferRat, Astrinox, and Massiv. It is used to steal credentials, enable unauthorized financial transactions, and exfiltrate data at scale, and is part of activity affecting more than 800 banking, cryptocurrency, and social platform applications. RecruitRat is primarily distributed through recruitment-themed social engineering, including fake job application files and fraudulent job-seeking websites, with victims tricked into sideloading malicious APKs. The broader campaigns also use phishing, smishing, homograph/lookalike domains, and attacker-controlled fake app or store pages.

Once installed, RecruitRat abuses Android Accessibility Services and overlay capabilities to monitor screen content and user interactions, perform clicks/swipes/typing, hide permission grants, and request additional high-risk permissions including access to contacts, device state, and SMS. It scans infected devices for installed banking, cryptocurrency, and social apps, then launches app-specific phishing overlays. RecruitRat uses fake login screens and fake lock-screen/PIN overlays to capture credentials, authentication codes, and device unlock secrets in real time. It has been reported to contain more than 700 fake login pages and to use an injectZip command to receive compressed HTML phishing overlays for more than 700 targeted applications. Reported capabilities across the observed campaigns include credential theft, OTP/SMS interception, contact theft, keylogging/tap logging, screen freezing, screen recording/streaming via MediaProjection, and large-scale data exfiltration.

RecruitRat uses a multi-stage installation process and persistence mechanisms. It can hide from the app drawer by replacing its icon with a blank transparent image. Zimperium reported that RecruitRat and SaferRat hide secondary payloads in res or assets directories and may load external DEX files with DexClassLoader. RecruitRat also employs anti-analysis and evasion techniques including ZIP-level APK tampering intended to disrupt tools such as APKTool and JADX, encrypted strings and API calls resolved dynamically through reflection, and RC4 encryption. For reconnaissance, it identifies installed apps via launcher-intent queries and a BotAddInfo command rather than relying on QUERY_ALL_PACKAGES, and encrypts the installed app list with RC4 before exfiltrating it to command-and-control infrastructure. C2 communications were reported over HTTPS, with RecruitRat additionally using RC4 encryption.

High-confidence indicators from the provided content include its Android APK delivery, recruitment/job-seeker lure theme, use of overlay phishing against banking and cryptocurrency apps, abuse of Accessibility Services and MediaProjection, transparent icon persistence to hide from the app drawer, RC4-encrypted app-list exfiltration, and support for more than 700 phishing/login overlays. A referenced repository also included files named RecruitRAT.md and recruitRat-apks.csv, updated with the note "IOCs added" on 2026-04-15.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

MITRE ATT&CK

Techniques & procedures

7 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

1 technique
T1566PhishingEvidence1

These malware families, named RecruitRat, SaferRat, Astrinox, and Massiv, employ various tactics like phishing and smishing to trick users into downloading malicious APK files.

Stealth

2 techniques
T1036MasqueradingEvidence1

SaferRat uses fake streaming service websites, while RecruitRat targets job seekers with fake job application files. Astrinox mimics business tools and was found on a fake Apple App Store page, though it currently targets Android.

T1564Hide ArtifactsEvidence1

SaferRat, for example, manipulates system navigation to make it difficult for users to delete it. RecruitRat, on the other hand, applies transparency effects, making it vanish from the app drawer.

Credential Access

3 techniques
T1056.001KeyloggingEvidence1

They can also intercept one-time passwords (OTPs) sent via text and use keylogging to record every tap.

T1528Steal Application Access TokenEvidence1

They can also intercept one-time passwords (OTPs) sent via text...

T1649Steal or Forge Authentication CertificatesEvidence1

Once installed, these malware families launch overlay attacks, presenting fake login screens over legitimate banking and crypto apps.

Collection

2 techniques
T1056.001KeyloggingEvidence1

They can also intercept one-time passwords (OTPs) sent via text and use keylogging to record every tap.

T1113Screen CaptureEvidence1

They abuse Accessibility Service permissions to freeze the screen, while secretly capturing credentials, contacts, SMS messages, and even recording the screen.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping7

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.