GhostBat RAT is a sophisticated Android malware campaign that has recently targeted users in India by impersonating Regional Transport Office (RTO) applications. Attackers distribute the malware through socially engineered messages, including WhatsApp and SMS, which contain shortened URLs leading to malicious APK files hosted on platforms like GitHub and compromised websites. Once a user installs the fake RTO app, GhostBat deploys a multi-stage dropper mechanism, utilizing obfuscation and native libraries to evade detection by static and heuristic-based security solutions. The malware presents convincing fake update prompts and overlay screens that mimic legitimate services such as mParivahan, tricking users into granting sensitive permissions like SMS access and overlay control. Upon obtaining these permissions, GhostBat is capable of harvesting banking credentials, SMS messages, and device identifiers, posing a significant risk to victims' financial and personal data. The campaign's use of Telegram bots for command-and-control (C2) communications allows attackers to remotely manage infected devices and exfiltrate stolen information efficiently. Security researchers have noted that GhostBat's modular architecture enables it to dynamically load additional payloads, further complicating detection and analysis. The campaign marks a resurgence in localized impersonation attacks, leveraging the high trust Indian users place in official RTO apps. Zimperium's Mobile Threat Defense (MTD) and zDefend solutions have demonstrated the ability to detect GhostBat's indicators of compromise (IOCs) on-device, even before public disclosure, highlighting the importance of advanced mobile security. On September 29, 2025, Zimperium detected an instance of GhostBat on a protected device, underscoring the malware's active deployment prior to widespread awareness. The attackers' strategy of combining trusted social engineering vectors with advanced evasion techniques makes the campaign particularly challenging to counter. Security experts recommend that organizations and individuals remain vigilant against unsolicited messages prompting app installations, especially those purporting to be from government agencies. The use of multi-stage droppers and dynamic code loading in GhostBat exemplifies the evolving tactics of Android malware authors. The campaign's reliance on Telegram for C2 communications also reflects a broader trend of leveraging popular messaging platforms for malicious purposes. The incident underscores the need for robust, on-device mobile threat detection capable of identifying both known and unknown malware variants. Organizations are urged to educate users about the risks of installing apps from unofficial sources and to implement mobile security solutions that can detect sophisticated threats like GhostBat. The GhostBat campaign serves as a warning about the increasing complexity and localization of Android malware targeting specific user populations.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Security researchers reported that GhostBat infections were being registered through a Telegram bot named "GhostBatRat_bot" and documented the malware's evasion techniques, including ZIP header manipulation, string obfuscation, native code execution, anti-emulation, and encrypted payload execution via a native C/C++ packer. Multiple outlets published analyses of the campaign on the same day, reflecting a single disclosure event.
A reemergent GhostBat RAT campaign began targeting Android users in India through malicious APKs distributed via hacked websites, WhatsApp, and SMS. The apps impersonated Indian Regional Transport Office services, including a fake mParivahan app, to steal UPI PINs and harvest banking-related SMS messages.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcesecurityonline.info
Open sourcezimperium.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.