Researchers have identified Fantasy Hub, a sophisticated Android Remote Access Trojan (RAT) marketed as a Malware-as-a-Service (MaaS) on Russian-language cybercrime forums. The spyware is distributed via a subscription model managed through Telegram bots, offering buyers a range of features including automated dropper builders, detailed documentation, and video tutorials. This professionalized service allows even inexperienced cybercriminals to deploy the malware by providing fake app kits and support for creating convincing phishing pages that mimic legitimate applications such as Telegram or banking portals.
Fantasy Hub enables attackers to gain full control over infected Android devices, exfiltrating SMS messages, contacts, call logs, images, and videos. The malware can intercept, reply to, and delete notifications, as well as initiate live audio and video streams using the device’s camera and microphone through encrypted WebRTC channels. Its design leverages social engineering and phishing to trick users into installing malicious apps, often by requesting a single SMS permission that unlocks broader device access. The RAT’s advanced capabilities and ease of use lower the barrier for cybercriminals, making it a significant threat to Android users worldwide.

Pull IOCs and campaign context straight into your stack.
2 events from the most recent confirmed update back to the earliest known activity.
Subsequent coverage detailed Fantasy Hub's use of Telegram bot infrastructure and WebRTC capabilities to manage infected Android devices and support real-time hijacking and espionage functions. Reports said the malware could expose banking, financial, and enterprise data from compromised devices.
Security reporting in November 2025 described Fantasy Hub as a Russian-linked malware-as-a-service platform for Android, marketed as spyware-for-rent with operator support and fake app kits. The platform was reported to enable full-device surveillance and credential theft on infected phones.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
6 references tracked. Mallory keeps watching after this page renders.
blog.knowbe4.com
Open sourcescworld.com
Open sourcethehackernews.com
Open sourcesecurityaffairs.com
Open sourcemalwarebytes.com
Open sourcesecurityonline.info
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.