Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Android RAT SURXRAT Grants Hackers Full Device Control and Data Exfiltration

SURXRAT is an Android Remote Access Trojan (RAT) marketed as a commercial malware-as-a-service (MaaS) on Telegram. This malware provides attackers with comprehensive device control capabilities and advanced data-stealing features.

SURXRAT is an Android Remote Access Trojan (RAT) marketed as a commercial malware-as-a-service (MaaS) on Telegram. This malware provides attackers with comprehensive device control capabilities and advanced data-stealing features.

SURXRAT integrates large-scale affiliate distribution, cloud-hosted command-and-control infrastructure, and experimental AI modules, posing a significant threat to Android users. The Indonesian operator of SURXRAT offers structured "Reseller" and "Partner" plans, which enable buyers to generate customized malware while maintaining centralized control over the infrastructure.

Reseller Plan: Includes permanent access, up to three builds per day, free server upgrades, and the ability to create and sell SURXRAT builds under operator pricing rules. Partner Plan: Priced higher, allowing for up to ten build accounts per day and the ability to build reseller networks.

Cyble Research and Intelligence Labs (CRIL) recently analyzed a new variant known as "SURXRAT V5," marketed through a dedicated Telegram ecosystem.

SURXRAT functions as a complete device-control platform focusing on credential theft, fraud, and extortion. Upon installation, it requests extensive permissions and exploits Android Accessibility Services to gain persistent, low-visibility control over the device.

SURXRAT is an Android Remote Access Trojan (RAT) marketed as a commercial malware-as-a-service (MaaS) on Telegram.
Joseph Cain · Thehackingpost

The malware collects a wide range of data, including SMS messages, contacts, call logs, Gmail data, device information, location, and browsing history. This enables attackers to intercept OTPs, harvest credentials, and conduct secondary financial fraud operations. SURXRAT also supports active device manipulation, such as placing calls and sending SMS messages.

Communication with its command-and-control (C2) is conducted via Firebase Realtime Database endpoints, which increases reliability and complicates network-based detection. Infected devices use a randomly generated UUID for registration and continuously exfiltrate data while polling for new commands.

SURXRAT's latest builds feature a conditional download of a large language model (LLM) module from Hugging Face, exceeding 23 GB. This module may be used to uniquely identify victims, monitor communications, and prepare for fraud activities such as OTP interception. The download is triggered when specific gaming apps are running or when target package names are remotely pushed.

Advertisement

The combination of MaaS commercialization, cloud-based C2, AI experimentation, and hybrid surveillance illustrates the rapid maturation of Android threats. SURXRAT also includes a ransomware-style screen-locker, enabling direct ransom-based extortion.

Security teams should enhance visibility on Android endpoints, monitor suspicious accessibility abuse and Firebase traffic patterns, and enforce strict controls on sideloaded apps.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories