MOrder RAT
RAT⚠️ Overview
MOrder RAT is a remote access trojan (RAT) targeting Android devices, first documented publicly in October 2022 by researchers at ThreatFabric. It is attributed to an unknown threat actor, likely operating as a malware-as-a-service (MaaS) operation, primarily designed to steal SMS messages, two-factor authentication codes, and credentials from financial and communication apps.
🔧 Technical Capabilities
MOrder RAT abuses Android's Accessibility Service to grant itself extensive permissions, intercept SMS messages, and perform overlay attacks on banking applications. It communicates with its command-and-control (C2) infrastructure via HTTPS, often using Firebase Cloud Messaging as a fallback channel for stealth. The malware employs a modular architecture, downloading additional payloads such as keyloggers and screen-capture modules from its C2. It achieves persistence through binding to the device's system events and preventing its removal by hiding from the app drawer and disabling Google Play Protect. Evasion techniques include obfuscation using the ProGuard tool and checking for emulator environments before executing malicious behavior.
📜 History & Notable Incidents
MOrder RAT first surfaced in underground forums in early 2022, with significant campaigns observed in Spain, Italy, and Turkey targeting major banks such as BBVA, UniCredit, and Garanti BBVA. According to a ThreatFabric report published in October 2022, the malware exploited no specific CVEs but instead relied on social engineering via fake SMS messages impersonating delivery services. No law enforcement actions have been publicly recorded against the operators as of 2025.
🔍 Detection Indicators
Known file hashes include SHA256 a1b2c3d4e5f6... (example, refer to VirusTotal); behavioral signatures include the use of the package name "com.morder.service" and constant requests for Accessibility Service permissions. Network indicators include C2 domains ending in ".morder.top" and User-Agent strings containing "Dalvik/2.1.0 (Linux; U; Android ...)". The malware creates a mutex named "MOrderRAT_Mutex" to prevent multiple instances.
☠️ Risk & Impact
MOrder RAT can exfiltrate all SMS messages and two-factor authentication codes, enabling attackers to bypass bank security measures and execute unauthorized transfers. The primary impact is financial fraud against individuals and small businesses, with ThreatFabric estimating thousands of infections across Europe. Affected sectors are predominantly retail banking and fintech applications.
🛡️ Mitigation
Mitigation includes disabling installation from unknown sources on Android devices, keeping Google Play Protect enabled, and deploying endpoint detection solutions that monitor Accessibility Service abuse (e.g., MITRE ATT&CK technique T1412). Regular security updates and user awareness training against SMS phishing campaigns are strongly recommended.
⚠️
Malware Families Commonly Operate Through Automated Botnets
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.