216.73.217.22

An Android RAT targets Telegram Users

· Published 28/06/2024 14:49 · Modified 28/06/2024 14:57

Export JSON

Essential information

Published
28/06/2024 14:49
Modified
28/06/2024 14:57
Tags
2024-06-28 android keylogger phishing rat spymax surveillance
Related entities
4 observables, 10 techniques (mitre), 1 malware

Description

This analysis discusses , a Remote Access Trojan () that targets devices and specifically aims at obtaining data from Telegram users. It employs techniques to trick victims into installing a malicious application disguised as the legitimate Telegram app. Once installed, gains extensive permissions, gathers sensitive information like keystrokes and location data, and transmits it to a remote command-and-control server. The malware also receives commands and additional payloads from the server, enabling remote control of the compromised device. The report outlines the technical details of 's operations, including its obfuscation methods, data exfiltration process, and communication with the command-and-control infrastructure.

External references