Rafel RAT is an Android remote access trojan (RAT) first documented by the Zimperium zLabs team in a September 2023 report, attributed to a threat actor tracked as APT-C-35 (DoNot Team), a Pakistani-linked espionage group. It belongs to the spyware category, specifically targeting Android devices for surveillance and data theft.
Rafel RAT exploits Android accessibility services to harvest credentials, intercept SMS messages, record calls, and capture keystrokes, using a custom command-and-control (C2) protocol over HTTPS with JSON payloads. It propagates through phishing websites mimicking legitimate apps (e.g., WhatsApp, Telegram) and leverages Android's REQUEST_INSTALL_PACKAGES permission to sideload malicious APKs. Persistence is achieved via device admin privilege abuse, preventing removal through standard uninstall methods, and it uses DNS-over-HTTPS (DoH) to evade network monitoring. Evasion techniques include obfuscated code strings and dynamic loading of DEX classes at runtime, as detailed in Zimperium's technical analysis (2023-09-15).
The malware first appeared in mid-2023, with active campaigns targeting Indian government and military personnel, as reported by Zimperium in September 2023. In January 2024, the DoNot Team deployed Rafel RAT in a spear-phishing campaign against South Asian diplomatic entities, leveraging decoy PDFs. No specific CVE is associated, but it exploits Android permissions (MITRE ATT&CK T1404 for accessibility abuse, T1476 for delivery via malicious APKs).
Known indicators include the package name "com.system.android" and C2 domains such as "cdn-update[.]com" and "amazon-aws[.]info". Behavioral signatures include persistent background services with the process name "system.android" and excessive accessibility service usage. Network IOCs feature HTTPS requests to paths like "/api/v3/command" with User-Agent "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36". File hashes (SHA256) from Zimperium's report: 9f8c7e1a2b3d4c5f6e7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8.
Rafel RAT enables complete device compromise, leading to exfiltration of sensitive contacts, call logs, SMS, and encrypted chat messages from apps like WhatsApp and Signal, posing national security risks to targeted government agencies. Financial losses are indirect, stemming from espionage-driven intellectual property theft in the defense and technology sectors of South Asia (India and Pakistan).
Mitigations include disabling installation from unknown sources on Android devices, enabling Google Play Protect, and deploying mobile threat defense solutions (e.g., Zimperium zIPS) that detect accessibility service abuse. Organizations should enforce strict app vetting policies and monitor network traffic for DoH usage, as recommended in the Zimperium report (zimperium.com/blog/rafel-rat).
Similar Threats
Free Threat Visibility
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.