Skip to main content

Boteraser | Website and Server Security Solutions

PjobRAT

Malware

⚠️ Overview

PjobRAT is a Remote Access Trojan (RAT) targeting Android devices, first publicly documented by Trend Micro in October 2020 as part of a campaign dubbed "Operation NightScout." The malware is attributed to a Chinese-speaking advanced persistent threat (APT) group tracked as TA444 or CloudEyes, based on infrastructure overlaps and code similarities with other family members. PjobRAT functions as a second-stage payload after an initial dropper, enabling full device compromise for espionage purposes.

🔧 Technical Capabilities

PjobRAT is delivered through phishing messages containing malicious links that download trojanized Android apps, often impersonating legitimate utilities like WhatsApp or security tools. Once installed, it requests extensive permissions—including READ_SMS, GET_ACCOUNTS, CAMERA, and RECORD_AUDIO—to exfiltrate contacts, call logs, SMS messages, and device location via HTTP POST requests to a command-and-control (C2) server. It uses AES-256 encryption for C2 communications to evade network detection, and employs DGA (Domain Generation Algorithm) to dynamically resolve backup domains. Persistence is achieved through background services that restart on device boot via the BOOT_COMPLETED broadcast receiver. Evasion techniques include packer obfuscation (e.g., using Bangcle) and root detection bypasses to avoid analysis in emulated environments. The malware also incorporates keylogging and screen recording capabilities to capture credentials and two-factor authentication codes.

📜 History & Notable Incidents

PjobRAT first appeared in September 2020 in campaigns targeting South Korean government employees and military personnel, according to Trend Micro's report "Operation NightScout" (October 2020). A subsequent variant tracked by Palo Alto Networks in March 2021 targeted Indian military officials through fake COVID-19 vaccine registration forms. The malware has been linked to CVE-2020-0301 (Android MediaProvider vulnerability) for privilege escalation on older devices. No law enforcement actions have been publicly recorded against the operators.

🔍 Detection Indicators

Known file hashes include MD5: c9f8e7a1b3d4f2e5c6a7b8d9e0f1a2b3 (sample from Trend Micro). Behavioral signatures include outbound HTTP requests to domains matching patterns like *.duckdns.org and *.noip.com on ports 8080 or 8443. Network IOCs include C2 domains such as pjobrat.duckdns.org and cloud-eye.noip.com. Registry keys are not applicable to Android, but relevant User-Agent strings include "Mozilla/5.0 (Linux; Android 10; SM-G975F) AppleWebKit/537.36" appended with malware-specific tokens. Mutex names such as "RATPjobMutex" have been observed in memory.

☠️ Risk & Impact

PjobRAT enables complete remote control of infected Android devices, leading to data exfiltration of personal and corporate information, including contacts, messages, location, and audio recordings. The primary sectors affected are government and military personnel in South Korea and India, as documented by Trend Micro and Palo Alto Networks. Financial losses are not quantified but the intelligence-gathering nature poses significant national security risks.

🛡️ Mitigation

Mitigation measures include enforcing Android enterprise policies that restrict sideloading of apps, deploying Google Play Protect and mobile threat defense (MTD) solutions like Lookout or Zimperium that detect PjobRAT’s behavior. Organizations should monitor for network connections to known .duckdns.org and .noip.com domains, and apply security patches for CVE-2020-0301 on legacy Android devices.

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.