Researchers reported that a threat actor is marketing Cyber Android RAT on criminal forums as a premium Android surveillance tool, offering access for about $499 per month or $2,500 lifetime. The malware is paired with a command-and-control platform called Cyber Nebula Core and is advertised as capable of stealing WhatsApp chat history, extracting cryptocurrency seed phrases, and conducting extensive device surveillance, including live microphone access and real-time video capture from front and rear cameras.
The malware also includes a hidden VNC capability that allows operators to remotely control an infected Android device as if they had physical access while remaining invisible to the victim. The reporting, citing analysis from Certo, indicates the tool is being positioned for serious criminal buyers rather than casual users, underscoring the continued commercialization of advanced mobile surveillance malware with both espionage and financial-theft use cases.

Pull IOCs and campaign context straight into your stack.
2 events from the most recent confirmed update back to the earliest known activity.
Mobile security firm Certo revealed that Cyber Android RAT uses a command-and-control platform called Cyber Nebula Core and supports hidden VNC control, microphone and camera access, keylogging, notification interception, WhatsApp message extraction, and remote file operations. Certo also said the malware can automate cryptocurrency theft from MetaMask and Binance wallets and appears intended for broad global deployment rather than region-specific targeting.
Researchers reported that a threat actor is marketing an Android remote access Trojan called Cyber Android RAT on criminal hacking forums as a premium surveillance and theft tool. The malware is offered for about $499 per month or $2,500 for lifetime access.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.