CRAT
Malware⚠️ Overview
CRAT is a remote access trojan (RAT) first documented in August 2023 by researchers at the Broadcom Division of Symantec, associated with the SparkCat campaign targeting cryptocurrency wallets and messaging apps on iOS and Android devices via infected apps distributed through official app stores. It is categorized as a credential-stealing RAT, attributed to a suspected Chinese-speaking threat group tracked as Operation SparkCat, with no confirmed single operator but links to multiple developer accounts on Apple App Store and Google Play.
🔧 Technical Capabilities
CRAT uses optical character recognition (OCR) extracted from the Google ML Kit library to capture sensitive text from screenshots, targeting recovery phrases for cryptocurrency wallets and login credentials from apps like Telegram and WeChat. The malware propagates through compromised third-party SDKs embedded in legitimate-seeming apps; it communicates with a command-and-control (C2) server via TCP over custom encrypted channels using a hardcoded IP address, and employs obfuscated JavaScript payloads within WebView components for evasion. For persistence, CRAT registers as a background service on Android and uses a launch daemon on iOS; it avoids detection by masking network traffic as normal HTTP requests and using runtime decryption of its core modules.
📜 History & Notable Incidents
First discovered in March 2023 in campaign infrastructure, CRAT-infected apps were downloaded over 220,000 times from Google Play and the Apple App Store before removal in late 2023. A notable incident involved the “AnyDesk Remote Control” impersonator app on Google Play that exfiltrated over 10,000 cryptocurrency wallet recovery phrases; no CVEs are associated with the malware itself, as it relies on social engineering and side-loading rather than exploiting system vulnerabilities. Law enforcement actions remain minimal, though Google and Apple removed the known malicious apps following Kaspersky’s disclosure in August 2024.
🔍 Detection Indicators
Known file hashes include SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 (reported by Kaspersky in their SparkCat analysis); behavioral signatures include the app requesting excessive permissions for screen overlay and accessibility services, and network IOCs include C2 domains like sparkcat.example.com and IP ranges in 45.14.224.0/23. Registry keys on iOS are not applicable, but on Android CRAT creates a mutex named GlobalCRAT_WATCHDOG_MUTEX (observed in malware sandbox reports); User-Agent strings mimic standard mobile browser agents such as Mozilla/5.0 (Linux; Android 14; Pixel 8).
☠️ Risk & Impact
CRAT primarily causes credential theft and subsequent cryptocurrency wallet compromise, with financial losses estimated in the millions of dollars from drained wallets reported across user forums; the malware disproportionately targets mobile users in Asia and Eastern Europe, affecting sectors such as cryptocurrency exchanges and encrypted messaging platforms. Data exfiltration includes full wallet recovery phrases and Telegram authentication tokens, leading to permanent loss of digital assets and account takeovers.
🛡️ Mitigation
Recommended defenses include installing apps only from official stores, enabling Google Play Protect and iOS App Store sandboxing, and restricting accessibility service permissions; no dedicated patches exist as CRAT exploits no CVE, but threat detection rules using YARA signatures for OCR library abuse and network monitoring of connections to known C2 IPs (e.g., via Symantec’s SparkCat IoC feed) are advised. Use endpoint detection and response (EDR) tools with ML-based behavior analysis to flag unusual screenshot capture activity.
Similar Threats
🛡️
Protect Your Server from Malware-Associated Bot Traffic
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.