Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to malware
Malware

TaxiSpy RAT

TaxiSpy RAT is an Android remote access trojan and banking malware family observed targeting Russian financial users, including Russian banks and financial institutions such as Alfa-Bank, as well as cryptocurrency, government, marketplace, and other sensitive apps. It combines banking-trojan functionality with full RAT capabilities and is described as a highly advanced Android banking malware.

Its capabilities include abuse of Android Accessibility Services and the MediaProjection API to capture inputs, keystrokes, lock-screen PINs, clipboard contents, SMS, contacts, call logs, installed apps, and notifications; automate actions; conduct VNC-like screen streaming and remote control; and hinder removal. It attempts to set itself as the default SMS handler to intercept SMS messages and one-time passwords. It also performs device reconnaissance, collecting device model, OS version, SIM data, and installed application information, and checks for targeted banking, government, crypto, and marketplace apps.

For credential theft and fraud, TaxiSpy RAT serves overlays against targeted Russian banking, cryptocurrency, and government applications to steal credentials. It uses Firebase push messages / Firebase Cloud Messaging as an auxiliary command channel, and communicates with command-and-control infrastructure via HTTP POST, WebSocket connections, and Firebase. The malware uses native-code obfuscation, including a native library named libsysruntime.so, to store sensitive logic and encrypted configuration values such as C2 addresses, Firebase credentials, bot identifiers, and worker keys, reportedly protected with customized XOR routines.

High-confidence indicators mentioned in the content include sample hash 67d5d8283346f850eb560f10424ea5a9ccdca5e6769fbbbf659a3e308987cafd and C2 IP 193.233.112.229. CYFIRMA highlighted TaxiSpy RAT as an active malware family, and Zimperium also reported on it in the context of newly identified Android malware families.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

MITRE ATT&CK

Techniques & procedures

4 distinct techniques documented for this family, organized by ATT&CK tactic.

Execution

1 technique
T1648Serverless ExecutionEvidence1

"Once installed, the apps urge users to enable accessibility services to realize their goals."; "TaxiSpy RAT... abuses Android's accessibility service..."; "The malware abuses accessibility permissions for persistent control"

Stealth

1 technique
T1497Virtualization/Sandbox EvasionEvidence1

"Besides incorporating runtime checks for emulated or analysis environments"; "advanced evasion techniques, such as native library encryption, rolling XOR string obfuscation"

Credential Access

1 technique
T1056.001KeyloggingEvidence1

"TaxiSpy RAT... collect... keystrokes"; "Mirax claims to offer... keystrokes"

Discovery

1 technique
T1497Virtualization/Sandbox EvasionEvidence1

"Besides incorporating runtime checks for emulated or analysis environments"; "advanced evasion techniques, such as native library encryption, rolling XOR string obfuscation"

Collection

1 technique
T1056.001KeyloggingEvidence1

"TaxiSpy RAT... collect... keystrokes"; "Mirax claims to offer... keystrokes"

Command and Control

1 technique
T1219Remote Access ToolsEvidence1

"full-fledged remote administration tools such as SURXRAT"; "enabling threat actors to gather sensitive data and execute commands"; "comprehensive remote control"

INDICATORS OF COMPROMISE

IOCs tracked for this family

3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
1 tracked

IPs, domains, and DNS infrastructure linked to this family.

Hashes
2 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

TypeValueLatest sighting
ip.v4●●●●●●●●●●●●View more in app1 month ago
hash.md5●●●●●●●●●●●●View more in app4 months ago
hash.sha256●●●●●●●●●●●●View more in app4 months ago
ACTIVITY FEED

Recent activity

4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching3

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping4

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.