Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Oblivion RAT Masquerades as Play Store Update to Spy on Android Users

A newly identified Android remote access trojan (RAT), known as Oblivion RAT, is causing significant concern within the mobile threat landscape.

A newly identified Android remote access trojan (RAT), known as Oblivion RAT, is causing significant concern within the mobile threat landscape.

Oblivion RAT is marketed as a malware-as-a-service (MaaS) platform and is available on cybercrime forums with subscription plans starting at $300 per month. Notably, it includes a web-based APK builder, a dropper generator, and a real-time command-and-control (C2) panel.

Research conducted by Certo Software has highlighted the comprehensive toolkit offered by Oblivion RAT, facilitating the deployment, infection, and control of compromised devices for attackers.

Oblivion RAT employs a two-stage infection process to deceive users into sideloading malicious applications. The attack begins with a dropper APK, typically distributed via messaging apps or social engineering campaigns. The dropper contains a compressed payload and three fake HTML pages that simulate the Google Play Store update process. These pages are self-contained and utilize inline elements to avoid detection.

The initial page appears as a download completion with a security scan, displaying messages such as "No malicious code" and "Verified developer." The second page resembles a Play Store listing with a fake developer name and an "Update" button, prompting users to grant installation permissions. The final page guides users through enabling sideloading, depicted as a standard procedure.

Oblivion RAT becomes fully operational in the second stage, executed through the platform's APK generator. It can operate in stealth mode or display a decoy web page while performing malicious actions in the background.

The malware exploits Android's Accessibility Service by replicating the settings page, tricking users into granting full control over the device interface. Once enabled, Oblivion RAT silently grants itself critical permissions, including access to SMS, storage, notifications, and device administration.

Despite its sophisticated delivery and control mechanisms, Oblivion RAT employs simple anti-analysis techniques, such as marking internal files as "encrypted" to confuse reverse engineering tools. Its configuration is stored in base64 format, exposing critical details such as the C2 server address (89.125.48.159:8888) and authentication tokens.

A newly identified Android remote access trojan (RAT), known as Oblivion RAT, is causing significant concern within the mobile threat landscape.
Henry Dalton · Thehackingpost

Upon connecting to its C2 server via self-signed TLS, Oblivion RAT provides attackers extensive control, including:

Real-time screen viewing and touch control via VNC. Keylogging of all user interactions. Full SMS access, including interception of OTP and 2FA codes. Sending messages from the victim’s number.

The malware also features a "Wealth Assessment" function that scans installed apps and categorizes them into banking, cryptocurrency, finance, and government services, aiding attackers in identifying high-value targets.

Indicator Type Notes

89.125.48.159 C2 IP Port 8888, self-signed TLS (CN=OblivionServer), AS 213702 (NL)

185.90.61.49 Panel IP Observed in C2 panel session

Advertisement

83.168.108.45 Secondary IP Port 443, AS 35179 (PL)

83.168.108.85 Secondary IP Port 443, AS 35179 (PL)

oblvn.sbs Panel Domain C2 panel and builder interface

fecf484b0fb268b1a6867057769a3e805abfc0b506cd022d37e0e50a9401714e RAT Payload Hash payload.apk (com.oblivion.client), VT: 14/67

d60d067c1239ec7db222ec18f7b8e20d85dd29ca5e8d4ddd86c55047374c3c48 RAT Payload Hash payload.apk (com.mail.ru), VT: 9/65

69a81fe8b53c1f5fa37363e32a2ed867a0c808776bdae155fc118c2de94a321a Dropper Hash Yandex.Archive.apk (com.yandexxxx.update), VT: 5/66

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories