Criminals used OmniRAT, a commercially sold remote administration tool, to take full control of Android devices through social-engineering lures and sideloaded apps. In one observed campaign, victims received SMS messages referencing the Stagefright flaw and were tricked into installing an APK named mms-einst8923.apk; the app then displayed a fake MMS notice, unpacked the malware, requested broad permissions, and enabled persistent surveillance and remote control. Avast reported that infected phones could also propagate the campaign by sending SMS messages to trusted contacts, while stolen data was sent to a Russian .ru command-and-control domain.
Researchers later linked GhostCtrl to OmniRAT as a variant or spinoff that significantly expanded the malware’s capabilities. Trend Micro said GhostCtrl was distributed through phishing links and masqueraded as legitimate Android apps, while adding obfuscation, shell-command execution, device rooting, ransomware-like screen locking, covert audio and video recording, SMS/MMS abuse, and encrypted data theft; it also reused infrastructure associated with the RETADUP worm campaign that hit Israeli hospitals. A separate GitHub repository listing for RAT.Android.OmniRAT containing a file named OmniRAT_Cracked.0e19cf.rar further indicated the malware family and its tooling were circulating beyond isolated campaigns.

Pull IOCs and campaign context straight into your stack.
3 events from the most recent confirmed update back to the earliest known activity.
A visible commit in the threatland TL-TROJAN repository added files under the RAT.Android.OmniRAT directory, which included an archive named OmniRAT_Cracked.0e19cf.rar. The commit was attributed to a user identified as "young thug" with the message "Adding some new files and changing permissions."
Trend Micro published analysis of GhostCtrl, describing it as a variant or spinoff of the commercially sold OmniRAT and detailing three versions with expanded capabilities including data theft, device control, ransomware-like locking, rooting, and covert audio/video capture. The report also linked GhostCtrl to RETADUP infrastructure and identified associated command-and-control domains.
Avast reported an in-the-wild campaign distributing a customized OmniRat variant to Android users through SMS social engineering that referenced the StageFright vulnerability and led victims to download an APK named mms-einst8923.apk. The malware installed persistent remote-access functionality, could send further SMS messages from infected devices, and exfiltrated data to a Russian .ru command-and-control domain.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
3 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourceblog.trendmicro.com
Open sourceblog.avast.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.