Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
remote-access-implantcybercrime-service-ecosystemphishing-campaign-intelligencecredential-access-method

Commercial Android RATs Abuse Accessibility Services for Full Device Takeover

Updated 3mo agoFirst seen Feb 25, 20262 sources

Two newly reported Android Remote Access Trojans (RATs)SURXRAT and Oblivion—highlight a continued shift toward commercialized, subscription-based mobile malware that enables non-expert criminals to gain full control of victim devices and exfiltrate data. Both threats are positioned as scalable offerings (i.e., Malware-as-a-Service) with structured sales models and distribution support, lowering the barrier to entry for surveillance, credential theft, and account takeover.

The reported infection chains rely heavily on social engineering to trick users into installing or activating malicious components, then escalating control by abusing Android Accessibility Services to bypass normal interaction and security boundaries. SURXRAT is described as modular and stealth-focused, distributed primarily via Telegram channels with tiered licensing/reseller options, and capable of broad data access (e.g., SMS, contacts, location, storage) once high-risk permissions are granted. Oblivion is marketed at roughly $300/month (with longer-term pricing tiers) and is delivered via fake Google Play update prompts; researchers reported capabilities including SMS theft for banking codes, keylogging, remote unlocking after reboot, and covert live screen viewing while a decoy “system updating” animation distracts the victim, with infrastructure reportedly able to manage 1,000+ concurrent victims (including via Tor).

Share:
Commercial Android RATs Abuse Accessibility Services for Full Device Takeover
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
Feb 25, 20264mo ago

Cyble reveals SURXRAT's cloud C2 and surveillance capabilities

The SURXRAT analysis described a social-engineering-based installation flow in which victims are tricked into installing a seemingly legitimate app that then abuses Accessibility Services and other risky permissions. Cyble said the malware uses Firebase Realtime Database for command-and-control and supports data theft, camera and audio surveillance, real-time command execution, and a ransomware-style screen locker.

Cyble links SURXRAT to ArsinkRAT and exposes MaaS operation

Cyble reported that the Android RAT SURXRAT is being sold through Telegram as a malware-as-a-service offering with tiered licensing and reseller plans. The researchers linked it to the older ArsinkRAT family, saying the developers likely repurposed and expanded earlier source code.

Researchers detail Oblivion's fake-update infection and device takeover features

Researchers said Oblivion commonly infects victims through fake Google Play update prompts, abuses Android Accessibility Services to silently gain permissions, and can steal SMS messages, log keystrokes, and remotely control devices while displaying a fake system update screen. They also reported backend infrastructure designed to support more than 1,000 concurrent victims and operation over Tor for anonymity.

Certo reports commercial Android RAT 'Oblivion' sold by subscription

Certo disclosed a new Android remote access trojan called Oblivion that is marketed on the public web with subscription pricing starting around $300 per month and a higher-priced lifetime option. The report said the malware lowers the barrier for stalkers and cybercriminals by making phone compromise easy to operate at scale.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

18 LINKEDOpen in app
Malware
1 linked
Affected products
9 linked
MagicosAndroidMiuiColorosOne UiOxygenosMiuiAndroidGoogle Services
Organizations
8 linked
HonorSamsung ElectronicsXiaomiHackread.comOneplusOppoCertoGoogle
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Commercial Android RATs Abuse Accessibility Services for Full Device Takeover | Mallory