Cellik Android Malware with One-Click APK Builder Let Attackers Wrap its Payload Inside with Google Play Store Apps
Cellik represents an advanced development in Android Remote Access Trojans (RATs), offering enhanced device control and surveillance functionalities that were previously associated with sophisticated spyware.
Cellik represents an advanced development in Android Remote Access Trojans (RATs), offering enhanced device control and surveillance functionalities that were previously associated with sophisticated spyware.
The newly discovered RAT facilitates full device access, integrated with Google Play Store connectivity, enabling attackers to embed malicious code within legitimate applications effectively.
Cellik has surfaced within cybercrime networks with the objective of making mobile attacks more accessible to operators with varying technical expertise, indicating a shift towards more democratized Android threats.
Once installed, the malware allows attackers complete control over the targeted devices. Cellik streams device screens in real-time with low latency, providing operators with a view of the victim's activity akin to accessing a remote VNC session.
Cellik live screen streaming (Source - iVerify)
Remote interactions are possible, as attackers can simulate taps and swipes on the infected device screen. The RAT intercepts all on-screen notifications, including private messages and one-time passcodes, granting operators full visibility into user communications and authentication attempts.
Once installed, the malware allows attackers complete control over the targeted devices.
Analysts at iVerify identified Cellik's advanced injection system, which facilitates overlay attacks and credential harvesting from banking applications and other sensitive platforms.
Live keylogger module in the Cellik control panel (Source - iVerify)
The injection toolkit enables attackers to deploy fake login screens over genuine apps or intercept data from installed applications. The control panel allows management of multiple injections across various apps without user detection.
A critical concern is Cellik's built-in APK builder with Google Play Store integration. This feature allows attackers to access the entire Google Play Store catalogue via the RAT interface, select legitimate applications, and generate malicious APK files embedding the Cellik payload within trusted apps. This process requires minimal technical effort, allowing even low-skilled operators to create convincing trojanized applications.
Hidden browser module interface used for stealth browsing (Source - iVerify)
The malware reportedly bypasses Google Play Protect detection by embedding its payload within established applications, potentially avoiding automated security assessments and device-level scanners that generally identify suspicious applications.
Cellik extends its functionalities beyond surveillance and control. It incorporates file system access for data exfiltration with encryption, a hidden browser for unauthorized web access and phishing, cryptocurrency wallet theft capabilities, and location tracking features.
The evolution of Android malware-as-a-service platforms exemplified by Cellik demonstrates how sophisticated mobile threats are now available in user-friendly subscription models, facilitating widespread deployment with minimal technical input from attackers.
Based on reporting by Cyber Security News.
