Android RAT SURXRAT Grants Hackers Full Device Control and Data Exfiltration
SURXRAT is an Android Remote Access Trojan (RAT) marketed as a commercial malware-as-a-service (MaaS) on Telegram. This malware provides attackers with comprehensive device control capabilities and advanced data-stealing features.
SURXRAT is an Android Remote Access Trojan (RAT) marketed as a commercial malware-as-a-service (MaaS) on Telegram. This malware provides attackers with comprehensive device control capabilities and advanced data-stealing features.
SURXRAT integrates large-scale affiliate distribution, cloud-hosted command-and-control infrastructure, and experimental AI modules, posing a significant threat to Android users. The Indonesian operator of SURXRAT offers structured "Reseller" and "Partner" plans, which enable buyers to generate customized malware while maintaining centralized control over the infrastructure.
Reseller Plan: Includes permanent access, up to three builds per day, free server upgrades, and the ability to create and sell SURXRAT builds under operator pricing rules. Partner Plan: Priced higher, allowing for up to ten build accounts per day and the ability to build reseller networks.
Cyble Research and Intelligence Labs (CRIL) recently analyzed a new variant known as "SURXRAT V5," marketed through a dedicated Telegram ecosystem.
SURXRAT functions as a complete device-control platform focusing on credential theft, fraud, and extortion. Upon installation, it requests extensive permissions and exploits Android Accessibility Services to gain persistent, low-visibility control over the device.
SURXRAT is an Android Remote Access Trojan (RAT) marketed as a commercial malware-as-a-service (MaaS) on Telegram.
The malware collects a wide range of data, including SMS messages, contacts, call logs, Gmail data, device information, location, and browsing history. This enables attackers to intercept OTPs, harvest credentials, and conduct secondary financial fraud operations. SURXRAT also supports active device manipulation, such as placing calls and sending SMS messages.
Communication with its command-and-control (C2) is conducted via Firebase Realtime Database endpoints, which increases reliability and complicates network-based detection. Infected devices use a randomly generated UUID for registration and continuously exfiltrate data while polling for new commands.
SURXRAT's latest builds feature a conditional download of a large language model (LLM) module from Hugging Face, exceeding 23 GB. This module may be used to uniquely identify victims, monitor communications, and prepare for fraud activities such as OTP interception. The download is triggered when specific gaming apps are running or when target package names are remotely pushed.
The combination of MaaS commercialization, cloud-based C2, AI experimentation, and hybrid surveillance illustrates the rapid maturation of Android threats. SURXRAT also includes a ransomware-style screen-locker, enabling direct ransom-based extortion.
Security teams should enhance visibility on Android endpoints, monitor suspicious accessibility abuse and Firebase traffic patterns, and enforce strict controls on sideloaded apps.
Based on reporting by GBHackers.
