MobeRat Android Remote Access Trojan
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Affected platforms
The following platforms are known to be affected:
Threat details
It is delivered, either through SMS or email messages, to the target device as an APK file. The infected device requires the Google Play Store settings to be altered so that untrusted applications can be installed before MobeRat can execute.
Once on a device. MobeRat has access to all files, user accounts and information. it can install, execute or delete applications, record phone and video calls and export SMS messages. At present it does not have the capability to steal financial credentials or log keystrokes, although it's creators have indicated this functionality will added in the future.
Remediation advice
To prevent and detect a trojan infection, ensure that:Remediation steps
| Type | Step |
|---|---|
|
Last edited: 17 February 2020 12:49 pm