An open-source Android remote administration tool known as Rafel RAT is being used by a number of threat actors, including cyber espionage groups, to achieve their operational goals by disguising itself as Instagram, WhatsApp, and other e-commerce and antivirus apps.
Check Point stated in an analysis released last week that “it gives malicious actors a powerful toolkit for remote administration and control, enabling a range of malicious activities from data theft to device manipulation.”
It has many features, including the capacity to erase call logs, wipe SD cards, stifle notifications, and even function as ransomware.
The Israeli cybersecurity organization previously brought attention to the use of Rafel RAT by DoNot Team read more about Multiple Threat Actors Deploying Open-Source Rafel RAT to Target Android Devices.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
