A newly discovered Android remote access trojan (RAT) known as Cellik has emerged in cybercrime markets, offering attackers complete control over infected devices and advanced real-time surveillance capabilities.
What sets it apart is the built-in Google Play Store integration, which allows cybercriminals to stealthily embed the RAT in legitimate apps with a single click.
Once installed, Cellik allows an operator to take complete remote control of a victim’s phone—streaming the device’s screen, simulating touches, and navigating the user interface.
This effectively turns the attacker’s panel into a live VNC-like session, showing the screen with minimal delay. The malware also captures all on-screen notifications, enabling interception of private messages and one-time authentication codes from messaging or banking apps.
Cellik acts as a fully featured spyware platform with modules for keylogging, camera and microphone access, and file system browsing. Attackers can quietly download, upload, or delete files and access cloud storage directories linked to the phone.
All communications between the device and the command server are encrypted, making data exfiltration more stealthy and more challenging to detect.
Hidden Browser, App Injection, and Play Store Bundling
Beyond passive monitoring, Cellik enables hidden web activity and app-injection attacks. A concealed browser component runs in the background, allowing attackers to open websites, fill out forms, and capture credentials without the user ever seeing it on their screen.
This feature can abuse saved cookies or autofill data to log in to online accounts, effectively enabling undetectable phishing or account takeover attempts.
The RAT’s injection toolkit can also overlay fake login pages on legitimate apps, including banking, email, and social networks. These injected overlays harvest credentials directly, with results streamed back to the attacker’s control panel.

The “Injector Lab” module supports custom-built overlays and multiple simultaneous attacks across different apps.
One of Cellik’s most alarming functions is its Play Store integration and automated APK builder. From the malware’s interface, attackers can browse Google Play, select any legitimate app, and then bundle the Cellik payload into it.
The builder generates a repackaged APK that appears to be the original app but secretly installs the RAT in the background.
The developers claim this method can bypass Google Play Protect, allowing malicious versions of trusted apps to spread undetected.
Cellik’s design demonstrates how Malware-as-a-Service platforms have industrialized Android malware development, lowering the barrier to entry for launching mobile spyware operations.
With real-time surveillance, data theft, and one-click rebranding tools, Cellik demonstrates how easily advanced capabilities once reserved for nation-state spyware are now accessible to everyday cybercriminals.
Find this Story Interesting! Follow us on Google News , LinkedIn and X to Get More Instant Updates