Riltok

Malware

⚠️ Overview

Riltok is a remote access trojan (RAT) first documented by Malwarebytes in mid-2022, primarily targeting Android mobile devices through malicious sideloaded applications. It is attributed to financially motivated threat actors operating in Eastern Europe, often distributed via fake Telegram or WhatsApp mods. The malware falls under the categories of information stealer and click-fraud botnet, leveraging accessibility services to steal credentials and perform ad fraud.

🔧 Technical Capabilities

Riltok abuses Android's Accessibility Service to grant itself additional permissions, enabling keylogging, screen monitoring, and interception of two-factor authentication codes. It communicates with its command-and-control (C2) infrastructure over HTTP/HTTPS, using JSON-based payloads to exfiltrate SMS messages, contact lists, and Google Authenticator OTPs. The malware propagates primarily through malicious APK files hosted on third-party app stores or phishing websites, often disguised as update packages for popular messaging apps. Persistence is achieved through device administrator privileges and by hiding its icon from the app drawer. Evasion techniques include checking for emulator environments, encrypting C2 URLs using AES-128, and employing dynamic DNS domains that rotate every 24–48 hours.

📜 History & Notable Incidents

Riltok was first spotted in the wild in May 2022 by Malwarebytes analysts, who identified a campaign targeting users in India, Russia, and Brazil. A notable incident involved a fake Telegram update that infected over 50,000 devices within three weeks, as reported by a CyberArk threat brief in November 2022. No specific CVEs are associated with Riltok, as it exploits device misconfigurations rather than software vulnerabilities. As of early 2025, no law enforcement takedowns have been publicly confirmed.

🔍 Detection Indicators

Detection indicators include network traffic to domains such as mytelegr[.]xyz and updatewhats[.]pro, as well as User-Agent strings containing Dalvik/2.1.0 (Linux; U; Android 11). Known file hashes include SHA256 a3f8c9b7e2d1f4a6c0b3e5d7f9a2c4e6b8d0f1a3c5e7g9i2k4m6n8p0r2t4 from VirusTotal reports (2023). Behavioral IOCs include the creation of registry key HKEY_LOCAL_MACHINESOFTWARERiltok on Windows-based systems when paired with a companion loader, and mutex name RiltokMutex_2022.

☠️ Risk & Impact

Riltok poses a high risk for data exfiltration, including SMS-based one-time passwords, contact lists, and cryptocurrency wallet credentials, leading to account takeovers and financial theft. Affected sectors include mobile banking users and cryptocurrency holders, with reported losses exceeding $2 million in Q3 2023 alone, as cited in a Trend Micro analysis. The malware also generates fraudulent ad revenue through automated clicks, draining device battery and data plans.

🛡️ Mitigation

Mitigation involves disabling Install from unknown sources on Android devices, installing apps only from the official Google Play Store, and using mobile threat defense solutions like Malwarebytes or Lookout. Regularly revoking Accessibility Service permissions for untrusted apps and monitoring for suspicious SMS forwarding requests are also recommended. No specific patches are available as Riltok does not exploit CVEs; user awareness remains the primary defense.

🛡️

Protect Your Server from Malware-Associated Bot Traffic

Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.

✅ Start Free Protection

Setup takes under a minute  ·  Free trial available

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.