s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-apk.capra_rat

📛 Threat Title

Malware family: CapraRAT

Category: CapraRAT First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `apk.capra_rat`. Printable name: CapraRAT.

Indicators of Compromise (0)

No indicators of compromise on this threat.

References (1)

Remediations (10)

  • web:izoologic.com

    A new report earlier this week revealed the re-emergence of the CapraRAT spyware, which targets mobile gamers and weapons enthusiasts through malicious Android applications. CapraRAT is a notorious Android remote access trojan malware leveraged by the Transparent Tribe threat group.

  • web:link.springer.com

    In this chapter, a detailed digital forensic investigation into CapraRAT Android malware , a specialized Remote Access Trojan (RAT), is presented, focusing on its structures, functions, behaviors, propagation methods, and impacts. Employing static analysis, the study uncovers that CapraRAT is designed to stealthily infiltrate Android devices, exploiting various vulnerabilities in the operating ...

  • web:malpedia.caad.fkie.fraunhofer.de

    According to PCrisk, CapraRAT is the name of an Android remote access trojan (RAT), possibly a modified version of another (open-source) RAT called AndroRAT. It is known that CapraRAT is used by an advanced persistent threat group (ATP) called APT36 (also known as Earth Karkaddan). CapraRAT allows attackers to perform certain actions on the infected Android device.

  • web:scholar.its.ac.id

    In this chapter, a detailed digital forensic investigation into CapraRAT Android malware , a specialized Remote Access Trojan (RAT), is presented, focusing on its structures, functions, behaviors, propagation methods, and impacts. Employing static analysis, the study uncovers that CapraRAT is designed to stealthily infiltrate Android devices, exploiting various vulnerabilities in the operating ...

  • web:securitricks.com

    Description APT36, also known as Transparent Tribe, has been observed using VPS provider Contabo to host malicious infrastructure for CapraRAT and Crimson RAT. Their latest tactic involves disguising spyware as the popular messaging app Viber, granting extensive permissions to record calls, read messages, and track location. The investigation traced the infrastructure, identified key ...

  • web:siliconangle.com

    The malware has primarily been used for surveillance, targeting Indian government and military personnel and human rights activities. CapraRAT was initially distributed via fake dating apps and ...

  • web:thehackernews.com

    Discover how Transparent Tribe's latest Android malware campaign targets mobile users, and learn about new threats like Snowblind in Southeast Asia.

  • web:www.fortinet.com

    FortiGuard Labs discovered new Symbiote and BPFDoor variants exploiting eBPF filters to enhance stealth through IPv6 support, UDP traffic, and dynamic port hopping for covert C2 communication.

  • web:www.pcrisk.com

    It depends on the capabilities of the malware . What is the purpose of CapraRAT malware ? This Android malware can access the camera, microphone, unique identification number, call logs/history, contact information, victim's phone number, and location information. Also, it can launch the installation packages of other applications.

  • web:www.researchgate.net

    Prevention and detection of eBPF-based malware is also explored, with the goal of providing organizations or legitimate users of eBPF techniques to harden their systems against eBPF-based malware ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.