RecruitRat
RecruitRat is an Android banking trojan/RAT family identified by Zimperium zLabs as one of four related campaigns alongside SaferRat, Astrinox, and Massiv. It is used to steal credentials, enable unauthorized financial transactions, and exfiltrate data at scale, and is part of activity affecting more than 800 banking, cryptocurrency, and social platform applications. RecruitRat is primarily distributed through recruitment-themed social engineering, including fake job application files and fraudulent job-seeking websites, with victims tricked into sideloading malicious APKs. The broader campaigns also use phishing, smishing, homograph/lookalike domains, and attacker-controlled fake app or store pages.
Once installed, RecruitRat abuses Android Accessibility Services and overlay capabilities to monitor screen content and user interactions, perform clicks/swipes/typing, hide permission grants, and request additional high-risk permissions including access to contacts, device state, and SMS. It scans infected devices for installed banking, cryptocurrency, and social apps, then launches app-specific phishing overlays. RecruitRat uses fake login screens and fake lock-screen/PIN overlays to capture credentials, authentication codes, and device unlock secrets in real time. It has been reported to contain more than 700 fake login pages and to use an injectZip command to receive compressed HTML phishing overlays for more than 700 targeted applications. Reported capabilities across the observed campaigns include credential theft, OTP/SMS interception, contact theft, keylogging/tap logging, screen freezing, screen recording/streaming via MediaProjection, and large-scale data exfiltration.
RecruitRat uses a multi-stage installation process and persistence mechanisms. It can hide from the app drawer by replacing its icon with a blank transparent image. Zimperium reported that RecruitRat and SaferRat hide secondary payloads in res or assets directories and may load external DEX files with DexClassLoader. RecruitRat also employs anti-analysis and evasion techniques including ZIP-level APK tampering intended to disrupt tools such as APKTool and JADX, encrypted strings and API calls resolved dynamically through reflection, and RC4 encryption. For reconnaissance, it identifies installed apps via launcher-intent queries and a BotAddInfo command rather than relying on QUERY_ALL_PACKAGES, and encrypts the installed app list with RC4 before exfiltrating it to command-and-control infrastructure. C2 communications were reported over HTTPS, with RecruitRat additionally using RC4 encryption.
High-confidence indicators from the provided content include its Android APK delivery, recruitment/job-seeker lure theme, use of overlay phishing against banking and cryptocurrency apps, abuse of Accessibility Services and MediaProjection, transparent icon persistence to hide from the app drawer, RC4-encrypted app-list exfiltration, and support for more than 700 phishing/login overlays. A referenced repository also included files named RecruitRAT.md and recruitRat-apks.csv, updated with the note "IOCs added" on 2026-04-15.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Techniques & procedures
7 distinct techniques documented for this family, organized by ATT&CK tactic.
Initial Access
1 technique
Initial Access
Stealth
2 techniques
Stealth
Credential Access
3 techniques
Credential Access
Recent activity
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android banking malware used in a large-scale campaign that abuses Accessibility and overlay features to hide itself, monitor screen content, capture PINs and credentials, and target banking, crypto, and social apps. RecruitRat was noted to apply transparency effects to vanish from the app drawer.
Android malware family distributed via fake job application files targeting job seekers. It performs overlay attacks against banking and crypto apps, abuses Accessibility Service permissions, steals credentials, contacts and SMS messages, intercepts OTPs, records screens, and uses keylogging.
Android banking trojan family distributed via recruitment-themed phishing sites. It uses droppers, hidden secondary payloads, DexClassLoader, RC4-encrypted exfiltration, fake lock-screen and banking overlays, app enumeration, screen capture, and visual stealth by replacing its icon with a transparent image.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.