Oblivion RAT Turns Fake Play Store Updates Into a Full-Service Android Spyware Operation
A newly identified Android remote access trojan, Oblivion RAT, has surfaced as a comprehensive malware-as-a-service (MaaS) platform, exploiting fake Google Play Store update pages to execute a full-scale spyware operation.
A newly identified Android remote access trojan, Oblivion RAT, has surfaced as a comprehensive malware-as-a-service (MaaS) platform, exploiting fake Google Play Store update pages to execute a full-scale spyware operation.
The trojan is notable for its advanced structure, which includes capabilities such as dropper delivery and real-time device control. It is available on underground forums for $300 per month, with a lifetime license priced at $2,200.
A web-based APK builder for the implant A dropper builder that generates counterfeit Google Play update pages A command-and-control (C2) panel for managing devices in real-time
The malware is distributed through messaging apps and dating platforms, where victims are misled into installing a fake Google Play update.
The infection involves a two-stage model:
The trojan is notable for its advanced structure, which includes capabilities such as dropper delivery and real-time device control.
The dropper APK contains a compressed RAT implant and three HTML pages simulating a Google Play update. The initial page shows a progress bar and a fake security scan. The second page mimics a Play Store listing, and the third page instructs users to enable app installation from unknown sources.
Upon completion, the second-stage implant operates in the background, providing the attacker with extensive control over the device, including access to SMS, keystrokes, financial data, and live screen sessions.
Oblivion RAT abuses Android's AccessibilityService to gain full device control. It requests access via a replica of the Android Accessibility settings screen. Once access is granted, the implant silently grants itself permissions, including SMS access and device admin rights, without user prompts.
The malware incorporates a hide_permission_process feature, which auto-dismisses system dialogs, rendering the permission process invisible to the user. Operators can conduct real-time VNC sessions, log keystrokes, and intercept SMS messages, including OTP codes and 2FA tokens.
An integrated "Wealth Assessment" feature categorizes the victim's apps into financial sectors, aiding attackers in targeting valuable accounts.
To mitigate risks, users should only download apps from the official Google Play Store and deny accessibility permissions to unfamiliar apps. Prompt requests for sideloading should be treated with caution. Organizations should enforce device management policies to block installations from unknown sources and monitor for suspicious AccessibilityService activity.
Based on reporting by Cyber Security News.
