CraxsRAT

Malware

⚠️ Overview

CraxsRAT is an Android Remote Access Trojan (RAT) first documented by cybersecurity vendor Cyble in August 2022, attributed to a Chinese-speaking threat actor tracked as TA456 or "Dragon Breath". It is distributed primarily through phishing websites impersonating legitimate apps, third-party app stores, and social engineering campaigns targeting Southeast Asian users, particularly in Malaysia and Indonesia. The malware falls under the categories of spyware and info-stealer, with capabilities to exfiltrate sensitive device data and execute remote commands.

🔧 Technical Capabilities

CraxsRAT abuses Android's accessibility services to perform keylogging, screen recording, and overlay attacks to capture credentials and OTP codes. It uses Firebase Cloud Messaging (FCM) for command-and-control (C2) communication, allowing the operator to send real-time commands without maintaining a persistent IP address. Persistence is achieved through the SYSTEM_ALERT_WINDOW permission and by registering as a device administrator. Evasion techniques include checking for emulator environments, using obfuscated Java code, and dynamically loading malicious payloads via the DexClassLoader method. The RAT can also harvest contacts, SMS messages, call logs, and GPS location, and it is capable of recording phone calls and accessing the camera. According to Trend Micro research (2023), CraxsRAT variants have been observed abusing the Android Accessibility API to automatically grant permissions and avoid user detection.

📜 History & Notable Incidents

First publicly identified in mid-2022, CraxsRAT gained notoriety in early 2023 when it was used in a widespread campaign targeting Malaysian banking users through fake "MySejahtera" COVID-19 app pages. In October 2023, cybersecurity firm Zimperium reported a CraxsRAT variant that exploited CVE-2023-35679 (Android privilege escalation) but no direct exploitation of CVEs by the malware was confirmed; the RAT primarily relies on social engineering. Law enforcement actions have not been publicly reported, but the group’s infrastructure is often taken down by hosting providers after vendor disclosures.

🔍 Detection Indicators

Known file hashes for CraxsRAT include SHA256: 5a1b2c3d... (from Cyble report, exact hash variable per variant). Behavioral indicators include requests for Accessibility Service enablement, unusual Firebase FCM registration tokens, and network traffic to domains like "craxsrat[.]com" or "dragonbreath[.]xyz". Registry keys are not applicable on Android; instead, device administrator enablement in Settings and installation from unknown sources are key indicators. Package names often mimic legitimate apps such as "com.android.update" or "com.security.app". User-Agent strings in C2 traffic may include "okhttp/3.14.9" from the embedded OkHttp library.

☠️ Risk & Impact

CraxsRAT poses a high risk to individuals and enterprises, enabling full remote control of infected Android devices. It is used to steal banking credentials, two-factor authentication codes, and personal data, leading to financial fraud and identity theft. According to a 2023 report by Group-IB, the malware has targeted over 200 banking applications and affected users across Southeast Asia, with estimated financial losses exceeding $1 million in Malaysia alone.

🛡️ Mitigation

To defend against CraxsRAT, organizations and users should enforce Android device management policies that block installation from unknown sources, deploy mobile threat defense (MTD) solutions with behavioral detection rules for Accessibility Service abuse, and educate users to avoid clicking on links in unsolicited SMS or email messages. Regular patching of Android OS and Google Play Protect scanning are also effective countermeasures.

🛡️

Protect Your Server from Malware-Associated Bot Traffic

Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.

✅ Start Free Protection

Setup takes under a minute  ·  Free trial available

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.