๐ธ๐พ๐ค Developer Origin2020 โ Present
Syria โ Developer Origin
CraxsRat was developed by a threat actor known as "EVLF" operating from Syria. Cyfirma's research identified the developer through cryptocurrency transaction analysis, Telegram activity patterns, and infrastructure registration records.
- Developer earned over $75,000 selling CraxsRat and CypherRAT lifetime licenses
- Over 100 paid licenses sold before cracked versions began circulating
- Builder tool features Arabic-language interface and documentation
- Distribution primarily through Telegram channels and dark web forums
- Single developer maintaining and updating the malware codebase since 2020
Source:Cyfirma Research
๐ธ๐ฌโก Active CampaignApril 2023 โ Present
Singapore โ Banking Phishing Campaign
Group-IB documented a sophisticated phishing campaign targeting Singaporean users, operated by Chinese-speaking threat actors. Attackers impersonated well-known local brands to distribute CraxsRat-infected Android applications.
- 10+ legitimate Singaporean brands impersonated including shopping platforms
- Fake anti-scam center apps used to trick security-conscious users
- Primary target: banking credentials and financial account access
- Attackers used CraxsRat's SMS interception to bypass 2FA authentication
- Campaign infrastructure traced to Chinese-speaking operators in East Asia
Source:Group-IB
๐ฒ๐พโก Active CampaignMay 2024 โ Present
Malaysia โ Banking Sector Targeting
The largest documented CraxsRat campaign by sample volume. Group-IB discovered over 190 unique malware samples targeting six major Malaysian economic sectors through convincing phishing websites that mimicked legitimate local businesses.
- 190+ unique CraxsRat samples discovered and analyzed
- Targeted sectors: banking, retail, infrastructure, F&B, delivery, logistics
- Phishing websites mimicking legitimate Malaysian brands served as primary distribution
- Malware payloads disguised as official banking apps and delivery tracking apps
- Significant financial losses reported among Malaysian mobile banking users
Source:Group-IB
๐ท๐บ๐ก Distribution HubNovember 2023
Russia โ Telegram Distribution Network
SOCRadar documented the hacker group "Dark Strom" actively selling CraxsRat version 6.7 through Telegram channels. The marketplace model allowed low-skill attackers to launch sophisticated mobile malware campaigns with minimal technical knowledge.
- CraxsRat v6.7 marketed as a 'powerful Android phone hacking tool'
- Sales conducted through Telegram channels with customer support
- Cracked versions amplified distribution beyond paying customers
- Telegram serves as primary marketplace for CraxsRat transactions globally
- Builder tool allows customization of C2 server, app icon, and permissions
Source:SOCRadar
๐ฎ๐ณโก Active Campaign2023 โ 2025
South Asia โ WhatsApp & Sideloading Distribution
South Asia (India and Pakistan) represents the highest-volume infection region for CraxsRat due to the prevalence of Android app sideloading and low Google Play Protect adoption rates. Malware spreads primarily through WhatsApp groups sharing modified APK files.
- Highest Android sideloading rates globally โ primary infection vector
- CraxsRat distributed via WhatsApp groups as 'premium' or 'modded' apps
- Low Google Play Protect adoption leaves devices vulnerable
- Budget Android devices often lack security updates and protections
- Significant victim base among users seeking free versions of paid apps
Source:Kaspersky Mobile Report
๐ฆ๐ชโก Active Campaign2023 โ 2024
Middle East โ Social Engineering Attacks
Lookout documented targeted CraxsRat campaigns across the UAE and Saudi Arabia leveraging sophisticated social engineering through WhatsApp. Attackers deployed malware through fake government service applications and fraudulent cryptocurrency investment platforms.
- Fake government e-service apps used as primary distribution vector
- Cryptocurrency investment platform scams deliver CraxsRat payloads
- WhatsApp social engineering targets high-net-worth individuals
- CraxsRat variants customized for Arabic-speaking victims
- Overlay attacks target banking and crypto wallet applications
Source:Lookout Threat Intelligence
๐บ๐ฆ๐ฅ๏ธ C2 Infrastructure2023 โ 2024
Eastern Europe โ C2 Infrastructure Hub
Multiple documented CraxsRat campaigns trace their Command & Control (C2) infrastructure to data centers in Eastern Europe. These servers handle all communication between infected devices and attacker control panels, including data exfiltration and remote command execution.
- C2 servers hosted in data centers with lenient abuse policies
- Infrastructure supports multiple CraxsRat campaigns simultaneously
- Communication uses encrypted channels to evade network detection
- Servers handle SMS interception data, keylog uploads, and screen captures
- IP addresses frequently rotated to avoid domain-based blacklisting
Source:Group-IB
๐จ๐ณโก Active Campaign2023 โ 2024
East Asia โ Chinese-Speaking Operators
Group-IB identified the operators behind the Singapore banking campaigns as Chinese-speaking threat actors based in East Asia. These operators used CraxsRat alongside custom Android payloads for comprehensive credential harvesting operations targeting Southeast Asian financial institutions.
- Operators identified through language analysis of infrastructure and code comments
- CraxsRat combined with custom credential-harvesting Android payloads
- Targeted multiple Southeast Asian financial institutions simultaneously
- Operated professional-grade infrastructure with redundant C2 servers
- Used automated scripts to process stolen banking credentials at scale
Source:Group-IB
๐ฉ๐ฟ๐ก Distribution Hub2023 โ 2024
North Africa โ Underground RAT Marketplace
ESET Research documented a growing underground marketplace for CraxsRat across North African Telegram channels. The region serves as a secondary distribution hub for Arabic-speaking threat actors, with localized Telegram groups offering tutorials, cracked versions, and technical support for CraxsRat deployment.
- Arabic-language Telegram channels provide CraxsRat tutorials and support
- Cracked versions circulate freely, lowering barrier to entry
- Region functions as secondary distribution hub for MENA-focused campaigns
- Local threat actors customize CraxsRat for regional banking applications
- Growing ecosystem of RAT-as-a-Service providers in the region
Source:ESET Research
๐ฐ๐ชโก Active Campaign2024 โ 2025
Sub-Saharan Africa โ Growing Infection Vector
Kaspersky's mobile threat report highlights Sub-Saharan Africa as an emerging CraxsRat infection region. Budget Android devices sold in the region often lack security updates and Google Play Protect coverage, making users particularly vulnerable to sideloaded malware including CraxsRat.
- Budget Android devices lack security patches and Play Protect integration
- Sideloaded apps are common due to limited Play Store accessibility
- Mobile money platforms present high-value targeting opportunity
- Infection rates increasing year-over-year as smartphone adoption grows
- Limited cybersecurity awareness among mobile-first internet users
Source:Kaspersky Mobile Report
๐ง๐ทโก Active Campaign2024
Latin America โ Banking Trojan Bundles
Recorded Future documented CraxsRat being bundled with regional banking trojans targeting Latin American financial institutions. Brazilian banking customers were primary targets, with distribution through fake banking apps and SMS phishing (smishing) campaigns directing victims to malicious download pages.
- CraxsRat bundled with established Brazilian banking trojans
- SMS phishing campaigns direct victims to fake banking app download pages
- Targets major Brazilian banks: Itaรบ, Bradesco, Banco do Brasil, Nubank
- PIX instant payment system credentials are a primary theft target
- Overlay attacks display convincing fake banking interfaces over real apps
Source:Recorded Future
๐ซ๐ท๐ก Distribution Hub2024 โ 2025
Global โ G700 Next-Generation Variant
Cyfirma published a detailed technical analysis of G700, the next-generation evolution of CraxsRat. G700 features advanced anti-analysis capabilities, encrypted C2 communications, and specifically targets cryptocurrency wallets and financial applications. This variant represents a significant escalation in CraxsRat's technical sophistication.
- Anti-emulator detection prevents analysis in sandbox environments
- Encrypted C2 communications evade network-level detection tools
- Runtime code injection bypasses static analysis and signature-based detection
- Specifically targets cryptocurrency wallets: MetaMask, Trust Wallet, Coinbase Wallet
- Enhanced ability to bypass Google Play Protect and third-party antivirus apps
Source:Cyfirma