New $300 Android RAT Boasts Automated Permission Bypass and Hidden Remote Control
The Oblivion Android Remote Access Trojan (RAT) is a significant new threat in the cybersecurity landscape. Unlike other Trojans in underground markets, Oblivion is a ground-up build, extensively tested before its release.
The Oblivion Android Remote Access Trojan (RAT) is a significant new threat in the cybersecurity landscape. Unlike other Trojans in underground markets, Oblivion is a ground-up build, extensively tested before its release.
Access to Oblivion is offered in a tiered pricing model: $300 for one month or $2,200 for lifetime access. The infrastructure remains under the control of the seller, as the source code is not provided.
The malware targets Android versions 8 through 16, allowing it to potentially infect most active devices. It has been analyzed and openly marketed on hacking forums.
Automated permission bypass Persistent access Hidden remote control channel
The Oblivion RAT is designed to be easy to operate, requiring minimal technical skill from attackers.
The Oblivion Android Remote Access Trojan (RAT) is a significant new threat in the cybersecurity landscape.
Oblivion includes a web-based APK Builder that enables operators to create malicious apps disguised as legitimate ones. The Dropper Builder creates fake update prompts to trick users into installing from unknown sources.
The malware can automatically grant itself permissions, including Accessibility Service access, bypassing Android's security prompts. It reportedly bypasses security layers of MIUI, One UI, ColorOS, MagicOS, and OxygenOS devices.
Oblivion uses VNC for live remote access and Hidden VNC (HVNC) for stealth sessions invisible to victims. It bypasses Android's permission restrictions, providing attackers with full interactive control while users see a fake "System updating…" screen.
Additional features include a "Screen Reader" module to extract content, exposing sensitive information like account details or wallet activity. Oblivion records SMS, 2FA codes, notifications, keylogs, and more while preventing removal by users.
The infrastructure can support over 1,000 active sessions, using anonymizing networks like Tor. Despite Google's efforts to control Accessibility Service abuse, Oblivion demonstrates that such countermeasures can be subverted.
Based on reporting by GBHackers.
