Oblivion RAT Masquerades As Play Store Updates In Expanding Android Spyware Campaign

A new Android remote access trojan, Oblivion RAT, has emerged on cybercrime forums, offering a highly polished malware-as-a-service platform.

Iverify discovered by Certo Software, this spyware is available to threat actors for $300 per month.

What makes Oblivion stand out is its production-ready infrastructure, which includes a web-based builder for creating the malicious implant, a dropper builder that creates convincing fake Google Play update screens, and a comprehensive command-and-control panel.

Security researchers recently obtained malware samples and reverse-engineered its complete infection chain to understand how it compromises devices and maintains control.

Infection Chain and Deceptive Tactics

Oblivion relies on a two-stage infection process that heavily uses social engineering to trick victims. Attackers distribute the initial dropper application through messaging apps or dating platforms.

Once downloaded, the dropper presents victims with a highly convincing, three-page sequence that appears to be a legitimate Google Play Store update.

The first screen displays a fake download progress bar alongside a security scan that falsely guarantees the application is verified and safe. The second screen shows a fabricated Play Store listing with a high developer rating and a prominent update button.

Fake download completion with security scan (Source: iverify)
Fake download completion with security scan (Source: iverify)

Once the second stage is installed, the malware focuses on gaining deep system access via Android’s Accessibility Service.

The operators use a customized builder to create a stealthy application that immediately requests accessibility permissions upon launch.

To trick the user, the malware displays a flawless replica of the legitimate Android accessibility settings screen. The attacker controls every piece of text on this fake page to reassure the victim.

Fake Play Store listing page (Source: iverify)
Fake Play Store listing page (Source: iverify)

Device Takeover and Threat Indicators

After successfully installing and bypassing security checks, the malware connects to its command server using an unencrypted configuration file.

This plaintext file easily reveals the server address, operator tokens, and operating modes to researchers. Once connected, the attacker gains access to a powerful control panel that offers real-time device surveillance.

Operators can view the compromised device screen, interact with it through touch commands, and monitor every keystroke the victim makes.

Iverify discovered, the malware registers itself as the default messaging application, it intercepts all incoming text messages before the victim ever sees them.

This capability allows attackers to capture one-time passwords and two-factor authentication codes seamlessly. The most concerning feature is the wealth assessment tool built into the control panel.

Fake Accessibility settings page (Source: iverify)
Fake Accessibility settings page (Source: iverify)

This feature automatically scans the victim’s device and categorizes installed applications into groups like banking, cryptocurrency, and microfinance. This immediate financial profile tells the attacker exactly which accounts are most valuable to target.

Security professionals should monitor their networks for the following infrastructure details associated with this ongoing campaign.

IndicatorTypeNotes
89.125.48.159C2 IPPort 8888, self-signed TLS (CN=OblivionServer), AS 213702 (NL)
185.90.61.49Panel IPObserved in C2 panel session
83.168.108.45Secondary IPPotential alternative infrastructure

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories