Emerging $300 Android RAT Leverages Automated Permission Bypass For Hidden Control

A newly discovered Android Remote Access Trojan (RAT), known as Oblivion, is catching the attention of cybersecurity experts due to its advanced capabilities and commercial availability.

Priced as low as $300 for a one-month subscription, Oblivion is designed to offer persistent, hidden control over Android devices, including the latest Android versions up to Android 16.

Unlike other RATs, Oblivion combines several sophisticated features, including automated permission bypass, deep persistence, and stealthy remote control, all bundled into a user-friendly package.

The $300 Malware Service

Oblivion is marketed through an online hacking forum, where it is advertised as a “keylogger” despite its true nature as a much broader infostealer.

The seller provides a detailed demonstration video showcasing its capabilities, which include bypassing Android’s security features, silently granting permissions, and controlling devices remotely.

The malware can be purchased through a subscription model, ranging from $300 for a one-month plan to $2,200 for lifetime access.

What makes Oblivion unique is not just its low cost, but its full-fledged capabilities, such as automated permission granting and hidden remote control.

The forum post promoting the RAT found by Certo’s researchers (Source: certosoftware)
The forum post promoting the RAT found by Certo’s researchers (Source: certosoftware)

Using a web-based builder, attackers can generate a custom APK that mimics legitimate apps, making it easy to deploy on victims’ devices without triggering suspicion.

Automated Permission Bypass and Hidden Control

One of Oblivion’s most significant features is its ability to bypass Android’s permission system without user intervention.

Normally, Android prompts users to approve sensitive permissions, such as Accessibility Service access. However, Oblivion sidesteps this by granting the necessary permissions silently, without any interaction from the victim.

This bypass works even on the most recent Android versions, including Android 15 and 16, making it an especially dangerous threat for a large number of active devices.

Once installed, Oblivion provides full control of the device via Hidden VNC (HVNC), allowing attackers to remotely control the phone without the user noticing.

The attacker can interact with the device in real time, all while a fake “System Update” screen or loading animation keeps the victim unaware.

Customising an app with the Dropper Builder (Source: certosoftware)
Customising an app with the Dropper Builder (Source: certosoftware)

This hidden session is fully customizable, allowing attackers to mimic an official update screen, a tactic commonly used by RATs to evade detection.

Additionally, Oblivion includes a keylogger that captures everything the victim types, including passwords, PINs, and two-factor authentication (2FA) codes.

It also enables the attacker to read and send SMS messages, view push notifications from banking apps, and even remotely uninstall or launch apps. With full access to the device’s data, the attacker can also bypass device lock screens using captured PINs or passwords.

One of Oblivion’s strongest points is its persistence. It uses advanced anti-removal techniques to prevent users from uninstalling or turning off the malware.

The RAT actively blocks attempts to revoke its permissions and can even hide its app icon, ensuring it remains unnoticed.

Even in environments with heavily customized Android security layers, such as MIUI (Xiaomi), One UI (Samsung), and ColorOS (OPPO), Oblivion remains functional and effective.

This combination of features makes Oblivion a powerful tool for financially motivated attackers, allowing them to operate undetected for extended periods, steal sensitive data, and take full control of a victim’s device without the user’s knowledge.

The malware gaining full control of the device (Source: certosoftware)
The malware gaining full control of the device (Source: certosoftware)

Protecting Yourself Against Oblivion

According to Certosoftware, to protect against threats like Oblivion, users should avoid sideloading apps from untrusted sources and be cautious of any pop-up messages urging them to install updates from outside the official Google Play Store.

Regularly reviewing the list of apps granted Accessibility permissions and running a security scan for hidden threats can also help detect and remove potential malware before it causes significant damage.

In conclusion, Oblivion is a serious threat that demonstrates how the commercialization of malware is lowering the barriers to cybercrime.

With its ability to bypass Android’s security features, its user-friendly deployment methods, and its persistent control over devices, Oblivion represents a significant challenge to both users and platform-level defenses.

Follow us on Google NewsLinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories