Oblivion RAT Masquerades as Play Store Update to Spy on Android Users
A newly identified Android remote access trojan (RAT), known as Oblivion RAT, is causing significant concern within the mobile threat landscape.
A newly identified Android remote access trojan (RAT), known as Oblivion RAT, is causing significant concern within the mobile threat landscape.
Oblivion RAT is marketed as a malware-as-a-service (MaaS) platform and is available on cybercrime forums with subscription plans starting at $300 per month. Notably, it includes a web-based APK builder, a dropper generator, and a real-time command-and-control (C2) panel.
Research conducted by Certo Software has highlighted the comprehensive toolkit offered by Oblivion RAT, facilitating the deployment, infection, and control of compromised devices for attackers.
Oblivion RAT employs a two-stage infection process to deceive users into sideloading malicious applications. The attack begins with a dropper APK, typically distributed via messaging apps or social engineering campaigns. The dropper contains a compressed payload and three fake HTML pages that simulate the Google Play Store update process. These pages are self-contained and utilize inline elements to avoid detection.
The initial page appears as a download completion with a security scan, displaying messages such as "No malicious code" and "Verified developer." The second page resembles a Play Store listing with a fake developer name and an "Update" button, prompting users to grant installation permissions. The final page guides users through enabling sideloading, depicted as a standard procedure.
Oblivion RAT becomes fully operational in the second stage, executed through the platform's APK generator. It can operate in stealth mode or display a decoy web page while performing malicious actions in the background.
The malware exploits Android's Accessibility Service by replicating the settings page, tricking users into granting full control over the device interface. Once enabled, Oblivion RAT silently grants itself critical permissions, including access to SMS, storage, notifications, and device administration.
Despite its sophisticated delivery and control mechanisms, Oblivion RAT employs simple anti-analysis techniques, such as marking internal files as "encrypted" to confuse reverse engineering tools. Its configuration is stored in base64 format, exposing critical details such as the C2 server address (89.125.48.159:8888) and authentication tokens.
A newly identified Android remote access trojan (RAT), known as Oblivion RAT, is causing significant concern within the mobile threat landscape.
Upon connecting to its C2 server via self-signed TLS, Oblivion RAT provides attackers extensive control, including:
Real-time screen viewing and touch control via VNC. Keylogging of all user interactions. Full SMS access, including interception of OTP and 2FA codes. Sending messages from the victim’s number.
The malware also features a "Wealth Assessment" function that scans installed apps and categorizes them into banking, cryptocurrency, finance, and government services, aiding attackers in identifying high-value targets.
Indicator Type Notes
89.125.48.159 C2 IP Port 8888, self-signed TLS (CN=OblivionServer), AS 213702 (NL)
185.90.61.49 Panel IP Observed in C2 panel session
83.168.108.45 Secondary IP Port 443, AS 35179 (PL)
83.168.108.85 Secondary IP Port 443, AS 35179 (PL)
oblvn.sbs Panel Domain C2 panel and builder interface
fecf484b0fb268b1a6867057769a3e805abfc0b506cd022d37e0e50a9401714e RAT Payload Hash payload.apk (com.oblivion.client), VT: 14/67
d60d067c1239ec7db222ec18f7b8e20d85dd29ca5e8d4ddd86c55047374c3c48 RAT Payload Hash payload.apk (com.mail.ru), VT: 9/65
69a81fe8b53c1f5fa37363e32a2ed867a0c808776bdae155fc118c2de94a321a Dropper Hash Yandex.Archive.apk (com.yandexxxx.update), VT: 5/66
Based on reporting by GBHackers.
