The Rise of RatOn: From NFC heists to remote control and ATS

Sept. 9, 2025, 10:06 p.m.

Description

A new Android banking trojan named RatOn has emerged, combining NFC relay attacks with remote access and automated transfer capabilities. Discovered by analysts monitoring the NFSkate threat group, RatOn targets cryptocurrency wallets and banking applications, particularly in the Czech Republic and Slovakia. The malware is distributed through adult-themed websites and employs a multi-stage infection process. RatOn features overlay attacks, automated money transfers, and cryptocurrency wallet takeovers. It demonstrates sophisticated capabilities, including screen casting, PIN interception, and extensive bot commands. The trojan's evolution from a basic NFC relay tool to a complex RAT with ATS functionality makes it a significant threat in the mobile malware landscape.

Date

  • Created: Sept. 9, 2025, 9:06 p.m.
  • Published: Sept. 9, 2025, 9:06 p.m.
  • Modified: Sept. 9, 2025, 10:06 p.m.

Indicators

  • ec3b852ffbede9fa4a5402bb0242df4955660b8b67ae3d21a12cd25ad40b3bb2
  • ea23506d4e1dd97b01b52d41e4f474f2dffa096b279f4e982073cad3e90f0bae
  • bf82609c55304c468996244d3ecc16348d9bea0891482ca724ffefcfaded8b66
  • ccb725738cded7e2380355a899475dcdd0fae29f77d8998b43cc1bb1bb600494
  • ce2b382ab6633a6bafee6f002c0ea94ab747cf4c98670fad437e5c5ca387a082
  • bba15ecc8404698530761a122d3f03310b5e775f2e1552b645135fefd27e625c
  • bbc7f2b5c17f90e4c054bc525d85cb96a791a9fe8c8295894fac50a9722fc908
  • 9a52126de022ea4d2fa065fbf368a8a08296f524d172e02e24ccf61f49eb7ad9
  • 98e09a8f01980d11177549eea9598ffd573e1be355a05ef7d31b85c6be9a38ce
  • 98cb893449ec52efe5b77286a66394f5627b070b7ec3bed715f14bc1b79c87db
  • 98c711801e9b89b4d0b4fb6c6fc5e8310ef3da226c7ac7261f04505384cd488a
  • 979d0331041d33d4af469f7daf7c5c5d268d1de0c231bdf7994229f00ad7a6a0
  • 7867e5c24f2ac72f3762c3acd31ffa0a931aac2377a4e6554a20963987dcedee
  • 6bce8f9c3ff27ba6348595898ef898262f853789cdbe96c5fa8a147c0f3b42b9
  • 49c29e87ba849a6afc82eb8a494d94123ebd70d04c43aebbe9f79d2572c2fecc
  • 3578222693be106eac90343c12f06454b6de6e19a50d31ae5105218c36514bbd
  • 15734c54d25341317a2f58bbc3c9ed3f8efa73af50fb5feb1ef46b6c3e02cab9
  • 01f746d75be3e744f78ad6a9f908bf6fc42b951caf58feb62a0369ffbc5ad836
  • 13f4b05abe78f7a5714f32ecddc9b5b463803c62cd8355f493b42af8cb4fa9db
  • www-core.top
  • tiktok18.world
  • marvelcore.top
  • evillab.world

Attack Patterns

  • NFSkate

Additional Informations

  • Finance
  • Slovakia