TaxiSpy RAT
TaxiSpy RAT is an Android remote access trojan and banking malware family observed targeting Russian financial users, including Russian banks and financial institutions such as Alfa-Bank, as well as cryptocurrency, government, marketplace, and other sensitive apps. It combines banking-trojan functionality with full RAT capabilities and is described as a highly advanced Android banking malware.
Its capabilities include abuse of Android Accessibility Services and the MediaProjection API to capture inputs, keystrokes, lock-screen PINs, clipboard contents, SMS, contacts, call logs, installed apps, and notifications; automate actions; conduct VNC-like screen streaming and remote control; and hinder removal. It attempts to set itself as the default SMS handler to intercept SMS messages and one-time passwords. It also performs device reconnaissance, collecting device model, OS version, SIM data, and installed application information, and checks for targeted banking, government, crypto, and marketplace apps.
For credential theft and fraud, TaxiSpy RAT serves overlays against targeted Russian banking, cryptocurrency, and government applications to steal credentials. It uses Firebase push messages / Firebase Cloud Messaging as an auxiliary command channel, and communicates with command-and-control infrastructure via HTTP POST, WebSocket connections, and Firebase. The malware uses native-code obfuscation, including a native library named libsysruntime.so, to store sensitive logic and encrypted configuration values such as C2 addresses, Firebase credentials, bot identifiers, and worker keys, reportedly protected with customized XOR routines.
High-confidence indicators mentioned in the content include sample hash 67d5d8283346f850eb560f10424ea5a9ccdca5e6769fbbbf659a3e308987cafd and C2 IP 193.233.112.229. CYFIRMA highlighted TaxiSpy RAT as an active malware family, and Zimperium also reported on it in the context of newly identified Android malware families.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Techniques & procedures
4 distinct techniques documented for this family, organized by ATT&CK tactic.
Execution
1 technique
Execution
Stealth
1 technique
Stealth
Credential Access
1 technique
Credential Access
Discovery
1 technique
Discovery
Collection
1 technique
Collection
IOCs tracked for this family
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Recent activity
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as one of 17 Android malware families detected in the wild over four months.
Android hybrid banking trojan/RAT targeting Russian banking/crypto/government apps; abuses accessibility and MediaProjection for data theft (SMS, contacts, PINs, keystrokes, etc.), uses overlays for credential theft, and supports remote control/commands via Firebase push messages; includes evasion and VNC-like control features.
Android remote access trojan (RAT) used to remotely control infected devices; reported targeting Russian banks/financial institutions.
Android banking malware with full RAT capability focused on Russian financial users. Abuses SMS handler and Accessibility permissions to intercept OTPs, keylog, capture screen/PIN, perform device reconnaissance, exfiltrate data (SMS, contacts, call logs, clipboard), and provide VNC-like remote control via WebSockets; uses Firebase Cloud Messaging as an auxiliary command channel and native-code obfuscation (libsysruntime.so) with encrypted runtime-decrypted configuration.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.