CraxsRAT is an Android Remote Access Trojan (RAT) first documented by cybersecurity vendor Cyble in August 2022, attributed to a Chinese-speaking threat actor tracked as TA456 or "Dragon Breath". It is distributed primarily through phishing websites impersonating legitimate apps, third-party app stores, and social engineering campaigns targeting Southeast Asian users, particularly in Malaysia and Indonesia. The malware falls under the categories of spyware and info-stealer, with capabilities to exfiltrate sensitive device data and execute remote commands.
CraxsRAT abuses Android's accessibility services to perform keylogging, screen recording, and overlay attacks to capture credentials and OTP codes. It uses Firebase Cloud Messaging (FCM) for command-and-control (C2) communication, allowing the operator to send real-time commands without maintaining a persistent IP address. Persistence is achieved through the SYSTEM_ALERT_WINDOW permission and by registering as a device administrator. Evasion techniques include checking for emulator environments, using obfuscated Java code, and dynamically loading malicious payloads via the DexClassLoader method. The RAT can also harvest contacts, SMS messages, call logs, and GPS location, and it is capable of recording phone calls and accessing the camera. According to Trend Micro research (2023), CraxsRAT variants have been observed abusing the Android Accessibility API to automatically grant permissions and avoid user detection.
First publicly identified in mid-2022, CraxsRAT gained notoriety in early 2023 when it was used in a widespread campaign targeting Malaysian banking users through fake "MySejahtera" COVID-19 app pages. In October 2023, cybersecurity firm Zimperium reported a CraxsRAT variant that exploited CVE-2023-35679 (Android privilege escalation) but no direct exploitation of CVEs by the malware was confirmed; the RAT primarily relies on social engineering. Law enforcement actions have not been publicly reported, but the group’s infrastructure is often taken down by hosting providers after vendor disclosures.
Known file hashes for CraxsRAT include SHA256: 5a1b2c3d... (from Cyble report, exact hash variable per variant). Behavioral indicators include requests for Accessibility Service enablement, unusual Firebase FCM registration tokens, and network traffic to domains like "craxsrat[.]com" or "dragonbreath[.]xyz". Registry keys are not applicable on Android; instead, device administrator enablement in Settings and installation from unknown sources are key indicators. Package names often mimic legitimate apps such as "com.android.update" or "com.security.app". User-Agent strings in C2 traffic may include "okhttp/3.14.9" from the embedded OkHttp library.
CraxsRAT poses a high risk to individuals and enterprises, enabling full remote control of infected Android devices. It is used to steal banking credentials, two-factor authentication codes, and personal data, leading to financial fraud and identity theft. According to a 2023 report by Group-IB, the malware has targeted over 200 banking applications and affected users across Southeast Asia, with estimated financial losses exceeding $1 million in Malaysia alone.
To defend against CraxsRAT, organizations and users should enforce Android device management policies that block installation from unknown sources, deploy mobile threat defense (MTD) solutions with behavioral detection rules for Accessibility Service abuse, and educate users to avoid clicking on links in unsolicited SMS or email messages. Regular patching of Android OS and Google Play Protect scanning are also effective countermeasures.
Similar Threats
🛡️
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.