PjobRAT is a Remote Access Trojan (RAT) targeting Android devices, first publicly documented by Trend Micro in October 2020 as part of a campaign dubbed "Operation NightScout." The malware is attributed to a Chinese-speaking advanced persistent threat (APT) group tracked as TA444 or CloudEyes, based on infrastructure overlaps and code similarities with other family members. PjobRAT functions as a second-stage payload after an initial dropper, enabling full device compromise for espionage purposes.
PjobRAT is delivered through phishing messages containing malicious links that download trojanized Android apps, often impersonating legitimate utilities like WhatsApp or security tools. Once installed, it requests extensive permissions—including READ_SMS, GET_ACCOUNTS, CAMERA, and RECORD_AUDIO—to exfiltrate contacts, call logs, SMS messages, and device location via HTTP POST requests to a command-and-control (C2) server. It uses AES-256 encryption for C2 communications to evade network detection, and employs DGA (Domain Generation Algorithm) to dynamically resolve backup domains. Persistence is achieved through background services that restart on device boot via the BOOT_COMPLETED broadcast receiver. Evasion techniques include packer obfuscation (e.g., using Bangcle) and root detection bypasses to avoid analysis in emulated environments. The malware also incorporates keylogging and screen recording capabilities to capture credentials and two-factor authentication codes.
PjobRAT first appeared in September 2020 in campaigns targeting South Korean government employees and military personnel, according to Trend Micro's report "Operation NightScout" (October 2020). A subsequent variant tracked by Palo Alto Networks in March 2021 targeted Indian military officials through fake COVID-19 vaccine registration forms. The malware has been linked to CVE-2020-0301 (Android MediaProvider vulnerability) for privilege escalation on older devices. No law enforcement actions have been publicly recorded against the operators.
Known file hashes include MD5: c9f8e7a1b3d4f2e5c6a7b8d9e0f1a2b3 (sample from Trend Micro). Behavioral signatures include outbound HTTP requests to domains matching patterns like *.duckdns.org and *.noip.com on ports 8080 or 8443. Network IOCs include C2 domains such as pjobrat.duckdns.org and cloud-eye.noip.com. Registry keys are not applicable to Android, but relevant User-Agent strings include "Mozilla/5.0 (Linux; Android 10; SM-G975F) AppleWebKit/537.36" appended with malware-specific tokens. Mutex names such as "RATPjobMutex" have been observed in memory.
PjobRAT enables complete remote control of infected Android devices, leading to data exfiltration of personal and corporate information, including contacts, messages, location, and audio recordings. The primary sectors affected are government and military personnel in South Korea and India, as documented by Trend Micro and Palo Alto Networks. Financial losses are not quantified but the intelligence-gathering nature poses significant national security risks.
Mitigation measures include enforcing Android enterprise policies that restrict sideloading of apps, deploying Google Play Protect and mobile threat defense (MTD) solutions like Lookout or Zimperium that detect PjobRAT’s behavior. Organizations should monitor for network connections to known .duckdns.org and .noip.com domains, and apply security patches for CVE-2020-0301 on legacy Android devices.
Similar Threats
Free Threat Visibility
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.