Snailsoft
∞ and beyond!
Staff Member
Moderator
SB Mod Squad ⭐
✔ Approved Releaser
eBook Releaser
Active User
Member for 2 years
- Gender
- Not specified
- Device
- 6502
- Country
- Canada
Rafel is what is known as a Remote Administrative Trojan.
Thanks to Google's own code to allow their own trojans onto Android, malicious hackers have been able to attack billions of devices.
Have you updated the software on your Samsung, Pixel or Xiaomi phone recently? If not, you might want to look away now. The cyber team at Check Point has just issued a new report warning just how big a risk you’re taking and urging you to update.
The team says it has been tracking the Rafel RAT across the United States, UK, China, Indonesia, Russia, India, France and Germany, and has detected 120 dangerous campaigns over the last two years—another reminder, they warn, “of how open-source malware technology can cause significant damage, especially when targeting big ecosystems like Android, with over 3.9 billion users worldwide.”
And this RAT is particularly nasty—definitely not something you want on your phone, sifting through all your personal data, sending anything it likes back to its handlers without you realizing—at least not until it’s too late. “Our findings,” Check Point says, “highlighted that most victims had Google (Pixel, Nexus), Samsung Galaxy A & S Series, and Xiaomi Redmi Series.” But many other devices were hit as well.
“It is crucial to keep your devices up-to-date with the most recent security fixes or replace them if they are no longer receiving them,” Check Point’s Alexander Chailytko says. “Prominent threat actors and even APT groups are always looking for the ways to leverage their operations, especially with the readily available tools such as Rafel RAT, which could lead to critical data exfiltration, leaked Two-Factor Authentication codes, surveillance attempts and covert operations.”
Rafel targets phones by way of non-Play Store installs. And while Google is adding better defenses around these “off-Play apps,” the sheer scale of the problem is huge; it has reported that its new real-time code-level scanning “has already detected over 5 million new, malicious off-Play apps, which helps protect Android users worldwide.”
Some of those threats are clearly more dangerous than others. “Rafel possesses all the essential features required to execute extortion schemes effectively,” Check Point says. “When malware obtains Device Admin privileges, it can alter the lock-screen password [and] prevent the malware’s uninstallation. If a user attempts to revoke admin privileges from the application, it promptly changes the password and locks the screen, thwarting any attempts to intervene.”
Check Point reports that 87% of all the infections it detected were on phones with older, unsupported Android versions. “But users of current Android versions should be concerned; this Android threat is capable of infecting a wide range of Android versions, from the oldest unsupported versions to the most recent ones.”
And that means even if you’re running Android 14, you need to keep your phone patched as regular security updates are released. Just this month, we saw Google address a Pixel vulnerability for which a targeted exploit had been found in the wild. When it comes to Android and malware, we’re in take no chances territory.
The team caught the Rafel RAT conducting remote surveillance, data exfiltration and ransomware, with victims “tricked” into downloading apps from outside Google’s Play Store ecosystem, apps that impersonate popular social media services, including some of the biggest, best known brands. Put at its simplest, sideloading apps onto a phone running an outdated version of Android is like playing Russian Roulette with multiple bullets in the gun—your chances of coming unstuck are dangerously high.
Rafel’s RAT menu of threats
Check Point
The social engineering behind these attacks relies on the fakery we are seeing ever more these days—impersonating popular apps to prompt an install. Apps impersonated by the Rafel RAT include WhatsApp and Instagram, which will be installed on most of the devices targeted. Once installed, the RAT requests various permissions to access sensitive apps and services, including contacts, call logs and—critically—text messaging, which enables the RAT to bypass 2FA security measures.
The RAT is programmed to retrieve contact lists, SMS messages, device info, location data, screenshots, and send them to its control server. But it can also wipe data from the phone, display fraudulent system messages, delete files and directories, and retrieve data and files stored on the device and forward those to its handlers.
Check Point advices users “to be cautious of links and applications sent by unknown senders or applications downloaded by unknown websites.” For anyone worried they might have downloaded something they shouldn’t, the team suggest “users should look for unusual behavior on their device, such as unexpected battery drain, increased data usage, or the presence of unfamiliar apps.”
Thanks to Google's own code to allow their own trojans onto Android, malicious hackers have been able to attack billions of devices.
Have you updated the software on your Samsung, Pixel or Xiaomi phone recently? If not, you might want to look away now. The cyber team at Check Point has just issued a new report warning just how big a risk you’re taking and urging you to update.
The team says it has been tracking the Rafel RAT across the United States, UK, China, Indonesia, Russia, India, France and Germany, and has detected 120 dangerous campaigns over the last two years—another reminder, they warn, “of how open-source malware technology can cause significant damage, especially when targeting big ecosystems like Android, with over 3.9 billion users worldwide.”
And this RAT is particularly nasty—definitely not something you want on your phone, sifting through all your personal data, sending anything it likes back to its handlers without you realizing—at least not until it’s too late. “Our findings,” Check Point says, “highlighted that most victims had Google (Pixel, Nexus), Samsung Galaxy A & S Series, and Xiaomi Redmi Series.” But many other devices were hit as well.
“It is crucial to keep your devices up-to-date with the most recent security fixes or replace them if they are no longer receiving them,” Check Point’s Alexander Chailytko says. “Prominent threat actors and even APT groups are always looking for the ways to leverage their operations, especially with the readily available tools such as Rafel RAT, which could lead to critical data exfiltration, leaked Two-Factor Authentication codes, surveillance attempts and covert operations.”
Rafel targets phones by way of non-Play Store installs. And while Google is adding better defenses around these “off-Play apps,” the sheer scale of the problem is huge; it has reported that its new real-time code-level scanning “has already detected over 5 million new, malicious off-Play apps, which helps protect Android users worldwide.”
Some of those threats are clearly more dangerous than others. “Rafel possesses all the essential features required to execute extortion schemes effectively,” Check Point says. “When malware obtains Device Admin privileges, it can alter the lock-screen password [and] prevent the malware’s uninstallation. If a user attempts to revoke admin privileges from the application, it promptly changes the password and locks the screen, thwarting any attempts to intervene.”
Check Point reports that 87% of all the infections it detected were on phones with older, unsupported Android versions. “But users of current Android versions should be concerned; this Android threat is capable of infecting a wide range of Android versions, from the oldest unsupported versions to the most recent ones.”
And that means even if you’re running Android 14, you need to keep your phone patched as regular security updates are released. Just this month, we saw Google address a Pixel vulnerability for which a targeted exploit had been found in the wild. When it comes to Android and malware, we’re in take no chances territory.
The team caught the Rafel RAT conducting remote surveillance, data exfiltration and ransomware, with victims “tricked” into downloading apps from outside Google’s Play Store ecosystem, apps that impersonate popular social media services, including some of the biggest, best known brands. Put at its simplest, sideloading apps onto a phone running an outdated version of Android is like playing Russian Roulette with multiple bullets in the gun—your chances of coming unstuck are dangerously high.
Rafel’s RAT menu of threats
Check Point
The social engineering behind these attacks relies on the fakery we are seeing ever more these days—impersonating popular apps to prompt an install. Apps impersonated by the Rafel RAT include WhatsApp and Instagram, which will be installed on most of the devices targeted. Once installed, the RAT requests various permissions to access sensitive apps and services, including contacts, call logs and—critically—text messaging, which enables the RAT to bypass 2FA security measures.
The RAT is programmed to retrieve contact lists, SMS messages, device info, location data, screenshots, and send them to its control server. But it can also wipe data from the phone, display fraudulent system messages, delete files and directories, and retrieve data and files stored on the device and forward those to its handlers.
Check Point advices users “to be cautious of links and applications sent by unknown senders or applications downloaded by unknown websites.” For anyone worried they might have downloaded something they shouldn’t, the team suggest “users should look for unusual behavior on their device, such as unexpected battery drain, increased data usage, or the presence of unfamiliar apps.”
