Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Cellik Android Malware with One-Click APK Builder Let Attackers Wrap its Payload Inside with Google Play Store Apps

Cellik represents an advanced development in Android Remote Access Trojans (RATs), offering enhanced device control and surveillance functionalities that were previously associated with sophisticated spyware.

Cellik represents an advanced development in Android Remote Access Trojans (RATs), offering enhanced device control and surveillance functionalities that were previously associated with sophisticated spyware.

The newly discovered RAT facilitates full device access, integrated with Google Play Store connectivity, enabling attackers to embed malicious code within legitimate applications effectively.

Cellik has surfaced within cybercrime networks with the objective of making mobile attacks more accessible to operators with varying technical expertise, indicating a shift towards more democratized Android threats.

Once installed, the malware allows attackers complete control over the targeted devices. Cellik streams device screens in real-time with low latency, providing operators with a view of the victim's activity akin to accessing a remote VNC session.

Cellik live screen streaming (Source - iVerify)

Remote interactions are possible, as attackers can simulate taps and swipes on the infected device screen. The RAT intercepts all on-screen notifications, including private messages and one-time passcodes, granting operators full visibility into user communications and authentication attempts.

Once installed, the malware allows attackers complete control over the targeted devices.
Vanessa Ray · Thehackingpost

Analysts at iVerify identified Cellik's advanced injection system, which facilitates overlay attacks and credential harvesting from banking applications and other sensitive platforms.

Live keylogger module in the Cellik control panel (Source - iVerify)

The injection toolkit enables attackers to deploy fake login screens over genuine apps or intercept data from installed applications. The control panel allows management of multiple injections across various apps without user detection.

A critical concern is Cellik's built-in APK builder with Google Play Store integration. This feature allows attackers to access the entire Google Play Store catalogue via the RAT interface, select legitimate applications, and generate malicious APK files embedding the Cellik payload within trusted apps. This process requires minimal technical effort, allowing even low-skilled operators to create convincing trojanized applications.

Advertisement

Hidden browser module interface used for stealth browsing (Source - iVerify)

The malware reportedly bypasses Google Play Protect detection by embedding its payload within established applications, potentially avoiding automated security assessments and device-level scanners that generally identify suspicious applications.

Cellik extends its functionalities beyond surveillance and control. It incorporates file system access for data exfiltration with encryption, a hidden browser for unauthorized web access and phishing, cryptocurrency wallet theft capabilities, and location tracking features.

The evolution of Android malware-as-a-service platforms exemplified by Cellik demonstrates how sophisticated mobile threats are now available in user-friendly subscription models, facilitating widespread deployment with minimal technical input from attackers.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories