Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Oblivion RAT

111
Global rank
84 infographic chevron month
Month rank
71 infographic chevron week
Week rank
0
IOCs

Oblivion RAT is a sophisticated Android Remote Access Trojan (RAT) offered as Malware-as-a-Service (MaaS) on cybercrime forums for as little as $300 per month. It equips even novice attackers with a complete toolkit, including a web-based APK builder, dropper generator mimicking Google Play updates, and a real-time C2 panel. The RAT enables full device takeover, data theft, and financial fraud through deceptive social engineering and Accessibility Service abuse.

RAT
Type
Unknown
Origin
1 February, 2026
First seen
23 August, 2026
Last seen

How to analyze Oblivion RAT with ANY.RUN

RAT
Type
Unknown
Origin
1 February, 2026
First seen
23 August, 2026
Last seen

IOCs

IP addresses
142.251.153.119
45.11.37.254
142.251.110.100
142.251.14.100
216.239.35.4
34.104.35.123
142.250.154.94
142.251.151.119
142.251.156.119
142.251.127.81
142.251.13.101
142.251.13.94
142.251.157.119
172.217.114.4
192.178.183.102
142.251.155.119
216.239.35.12
142.251.20.94
94.228.169.52
142.251.150.119
Hashes
bb9f8df61474d25e71fa00722318cd387396ca1736605e1248821cc0de3d3af8
f9d31b278e215eb0d0e9cd709edfa037e828f36214ab7906f612160fead4b2b4
8e89bbb65cdd9fffc294660ba897eb044424a9f80306f1f1f165aeea01d9b8ec
8582a0494656ad4d7e3102f09e37bf6e9bd196c3470a9d54bfebd48462e78a08
fd41cac9d6e0c58fffefb8da5a446e05d2ac8d5908eddb6fdb98e095644d332d
e9fc2f1278f2d778bf77e741bb2229fac341d4916dd5c21c132b71ae33de49a4
d32819b952dee7c012a4355d2b2284b5ad70c8329e90444334b5f94d56fed5a6
4aef9aa4a99ab2d32579474e7ceb908ebcc479b615582ad104eef7b4fe7c1201
4b8473de25bc7389e30c19df43763dc4f7ce9e646023ce6ff182aefc5a8a5c54
e0cb7b975c9cb43a0bdb399aaa40d6170c7ae9d81f6f80c111f13565d5f5c840
c455c0a140472a76f5bb65487a8930521a63c26307e232007ee95937492a0079
343c1174ab82c87ffc5b8a36505a37df4d426b856aafe78e68d5acf482e2466e
712bf70e3c0028fbbe7a461f3f70cbe3f950a66de8895b337d15e61da136d383
32ac0b978c8c5f1d0d70fd8d84710d02151c3b110926eb146dc996ce28d6a6c1
717c1ad56376af78bb1c04beeefe5a16e5a5fccfdd79d52795fb6548c104dede
e29b74190a0a6232a704a0cd15beffbe0699cc3b6ebbdce399308913622eb6c1
00fbb8e56160d1be1c223286994140a0a1d08928fe36a841764ecf0d904140c7
f167f7c5bb7de69382a7a0478145d601dcde832345b782377a390c74fb9e3141
4990a7a247451865c66b7cea2acfe6e375e4f091bde55b728fcb51d4dc5c6181
c398b05af9d1d78e5c04e5a2fc1f864a38d72f4c712e6a43d7a0220a8507aca2
Domains
google.com
s3.eu-central-003.backblazeb2.com
www.google.com
connectivitycheck.gstatic.com
edgedl.me.gvt1.com
clientservices.googleapis.com
update.googleapis.com
staging-remoteprovisioning.sandbox.googleapis.com
play.googleapis.com
time.android.com
static.apkpures.xyz
googleads.g.doubleclick.net
cdn.mediago.io
r.cdnpure.com
a.apkpures.xyz
trace-eu.mediago.io
ampcid.google.it
udbdf.apkpure.com
static.admaster.cc
static.apkpure.com
URLs
https://s3.eu-central-003.backblazeb2.com/edgecdn-k7m2qx/172e5a4f627ebe3d.bin
http://connectivitycheck.gstatic.com/generate_204
https://www.google.com/generate_204
https://staging-remoteprovisioning.sandbox.googleapis.com/v1:fetcheekchain
https://staging-remoteprovisioning.sandbox.googleapis.com/v1:signcertificates?challenge=aaaboc0nuiqbilsty5ubdcfqrzev6oi_h2prfxa=&request_id=912eef10-51b5-4b8a-b7de-f9fcd487b7e1
https://clientservices.googleapis.com/chrome-variations/seed?osname=android_webview&milestone=137
https://update.googleapis.com/service/update2/json?cup2key=15:auw1kvc_cwjezxmkugrauyc7oeijpjxjitul-bfcnq4&cup2hreq=47154da86e116b120ddc918c71618eaccd5f71410c9eb1f813ab529780abbc95
https://update.googleapis.com/service/update2/json
https://edgedl.me.gvt1.com/edgedl/release2/chrome_component/acmmwq7dser4xm5sepzjv74g65vq_2023.7.28.10/cffplpkejcbdpfnfabnjikeicbedmifn_2023.07.28.10_all_acgbwixmcanakp2bkoppyszsbkrq.crx3
http://play.googleapis.com/generate_204
https://update.googleapis.com/service/update2/json?cup2key=15:n91pksr8zlxv-he0dqu-pnsmlnbip-v8mzit0ana81w&cup2hreq=7191f1f5270c9ca5860ce94a7738938052b19b604812648a443823beccf0032b
http://www.google.com/gen_204
http://193.111.117.72:8080/ping
https://staging-remoteprovisioning.sandbox.googleapis.com/v1:signcertificates?challenge=aaabocngx1obilsty-ytcg2bvrdyhfdfo-wbhfw=&request_id=e078412c-b726-46f8-9982-3c02f43fdcb9
https://update.googleapis.com/service/update2/json?cup2key=15:rnqmivzys0b1boqbwmj4knb73oi_wa5m8zikfl8anks&cup2hreq=53cdedb6d60e217285025b820be78f83861ec834c4a854d80d103fee4a7ecdd5
https://staging-remoteprovisioning.sandbox.googleapis.com/v1:signcertificates?challenge=aaaboa_2zbybilsty9epugtk1ztoglrwb4accng=&request_id=7e73ffed-a311-42fc-86e1-b97cabf8c4b0
https://update.googleapis.com/service/update2/json?cup2key=15:qmyc-cpbsrof8yf5tqlc0b2eebtyn-6w6zlrimdnww8&cup2hreq=29421d2f45f92d82623855883a86ad60db4971e59aaa2f85a8ca2820469361cf
https://m.apkpure.com/ru/stalkgram/com.adriva.whatsupp/download/1.21
https://m.apkpure.com/language_v1034.js?hl=ru-ru
https://i.apkpure.com/user_v1002.js?hl=ru-ru&mobile=1&r=0.3789245229764755
Last Seen at

Recent blog posts

post image
North Korean IT Workers Scheme: Detection IOC...
watchers 6086
comments 0
post image
Hunt Malware & Phishing Threats with ANY....
watchers 5931
comments 0
post image
Mirage2FA Hijacks Companies’ Microsoft 365 Se...
watchers 19043
comments 0

Fake Updates, Real Takeover: Inside Oblivion RAT’s Stealthy Assault on Android Devices

Key Takeaways

  1. Oblivion RAT is a new Android MaaS RAT sold for $300/month with built-in APK and dropper builders for easy deployment.

  2. It uses fake Google Play update pages and Accessibility Service abuse for silent, permissionless installation.

  3. Core features include hidden VNC control, SMS/2FA interception, keylogging, and “Wealth Assessment” for targeting financial apps.

  4. Businesses face risks of data theft, fraud, and compliance breaches, especially in finance, defense, and mobile-heavy sectors.

  5. The threat has already infected over 7,500 devices since early 2026, with campaigns scaling rapidly via social engineering.

  6. Use ANY.RUN TI Lookup to hunt Oblivion proactively: search IOCs and enrich investigations instantly to block emerging variants before they strike.

destinationIP:"193.221.200.242".

Malicious IP linked to Oblivion RAT Malicious IP linked to Oblivion RAT

  1. Analyze suspicious Android files in ANY.RUN’s Interactive Sandbox for interactive, real-time visibility into RAT behavior and full threat context.

View analysis session

Oblivion RAT analysis in Interactive Sandbox Oblivion RAT fresh sample analysis in Interactive Sandbox

What is Oblivion RAT Malware?

Oblivion RAT is a newly emerged Android Remote Access Trojan (RAT) sold as a Malware-as-a-Service (MaaS) platform on underground cybercrime forums first publicly reported in February 2026. For a subscription starting at $300 per month, any would-be attacker gains access to a toolkit capable of silently hijacking nearly every Android device in active use today, no coding skills required.

The platform targets Android versions 8 through 16, covering virtually the entire active Android install base. Its combination of automated permission bypass, a Hidden VNC remote control channel, real-time OTP interception, and deep anti-removal persistence makes it one of the most capable and accessible mobile threats observed to date.

The platform consists of three core components that work in concert: a web-based APK Builder, a Dropper Builder, and a real-time command-and-control (C2) panel. Together these tools allow operators to build customized malware, deploy it convincingly to victims, and then manage hundreds of compromised devices through a single dashboard.

The APK Builder lets operators configure the malicious app's name, icon, and package name through a web interface. Two deployment modes are available. In stealth mode, the installed app immediately requests Accessibility Service permissions in the background, hides its icon from the home screen, and shows no visible interface at all.

In webview mode, the app opens a legitimate-looking website as a decoy while silently acquiring the same permissions behind the scenes. Default package name patterns (com.darkpurecore* for the dropper, net.darkhyperapps* for the implant) are visible across analyzed samples, providing a valuable detection foothold for defenders.

The Dropper Builder generates pixel-perfect imitations of the Google Play Store update flow. Victims are walked through three convincing pages: a fake download progress bar with a simulated security scan, a counterfeit Play Store listing complete with a developer name of 'LLC Google,' a 4.5-star rating, and an Update button, and finally a step-by-step guide framing sideloading as 'a standard security procedure.' All three pages auto-translate into the target's language, with confirmed presets for English and Russian.

On the technical side, Oblivion uses several anti-analysis techniques. Its most notable trick is a 'fake ZIP encryption' flag embedded in the APK that causes standard reverse-engineering tools like jadx and apktool to halt and report the file as encrypted. In reality, the contents are ordinarily compressed and can be extracted manually.

The malware's C2 configuration is stored as a plaintext Base64 string without meaningful encryption, inadvertently exposing critical infrastructure details including the C2 server address and operator authentication tokens prefixed with 'OBL_'. C2 communication runs over self-signed TLS with the Common Name set to 'OblivionServer,' another detection-friendly indicator.

How Oblivion RAT Threatens Businesses and Organizations

Oblivion RAT poses a severe risk to enterprises by turning employee or contractor Android devices into persistent surveillance and fraud tools. It silently intercepts SMS-based 2FA codes, push notifications (including from corporate banking or email apps), keystrokes, contacts, call logs, GPS location, and files. In a BYOD or mobile-first environment, this enables credential theft for corporate accounts, data exfiltration, and even remote app control that could compromise internal systems.

The “Wealth Assessment” feature specifically flags financial apps, making it ideal for targeted business email compromise or account takeover fraud. Organizations face regulatory risks (e.g., GDPR, CCPA violations from stolen personal data), financial losses from fraud, and reputational damage. Its ability to bypass Google Play Protect (with some samples showing low detection rates) and major OEM security layers amplifies the threat to mobile endpoints, which are often the weakest link in corporate defenses.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

Victimology: Which Industries Are Most at Risk?

While public data on specific victims remains limited due to the malware’s recency, Oblivion RAT’s design points to broad targeting via social engineering on messaging and dating apps. Over 7,500 infected devices have been observed globally since early 2026, with campaigns lasting an average of 21 days.

Potentially High-Risk Sectors:

  • Financial Services & Fintech: Wealth Assessment prioritizes banking/crypto apps; SMS/2FA interception enables account takeovers.

  • Defense, Media & Tech Research: Reported targeting in some campaigns; access to sensitive communications and location data.

  • Healthcare & Government: Mobile workforce handling sensitive data; potential for notification interception and surveillance.

  • Any Enterprise with BYOD/Mobile Workforce: High exposure via sideloaded apps; persistence on employee devices accessing corporate resources.

According to ANY.RUN threat intelligence data, the most recent Oblivion campaigns have been targeting IT, Telecom and Healthcare companies:

threatName:"oblivion".

Industries targeted by Oblivion RAT Industries targeted by Oblivion RAT

Oblivion's MaaS business model means attackers do not need specialized knowledge of any one sector. The Wealth Assessment module performs automatic target prioritization, the platform itself identifies which victims are most financially valuable. Organizations in any sector with employees using Android devices for work or authentication are within scope.

How Does Oblivion RAT Get In the System and Spread?

Oblivion employs a two-stage infection chain initiated through targeted social engineering:

1. Dropper Stage: Distributed via messaging/dating apps. The dropper APK contains a compressed payload and three embedded HTML pages mimicking Google Play update flows (progress bar, fake “LLC Google” listing, sideloading instructions). It tricks users into enabling unknown sources and installing the implant.

2. Implant Stage: The payload uses a fake Accessibility Service settings screen to gain control. Once enabled, it auto-grants permissions (SMS, notifications, storage, device admin) invisibly and hides all dialogs.

Key Spread Vectors: Phishing links in chats, fake app updates. No email or drive-by downloads reported, purely user-assisted sideloaded APKs. Persistence via boot receiver and anti-removal hooks ensures long-term access.

How Does Oblivion RAT Malware Function?

After installation:

  • Permission Escalation & Stealth: Abuses Accessibility Service for UI automation, keylogging, and dialog suppression. Hides icon and processes; blocks removal attempts.

  • Remote Control: Full HVNC with MediaProjection for touch input; victims see fake overlays while attackers interact live. Includes Screen Reader mode for banking apps.

  • Data Exfiltration: Intercepts SMS/OTP/2FA, notifications, keystrokes (timestamped by app), contacts, calls, location, files. Wealth Assessment scans apps for financial targeting.

  • C2 Communication: Self-signed TLS to IPs like 89.125.48.159:8888; config in plaintext base64.

  • Anti-Analysis: Fake ZIP encryption flag (bit 0x0809) fools tools like apktool/jadx.

Oblivion capabilities and commands Oblivion capabilities and commands

Sandbox Analysis of Oblivion Sample

See the detonation of Oblivion

Oblivion RAT in action in the sandbox Oblivion RAT in action in the sandbox

The analyzed sample of Oblivion RAT begins execution by performing basic environment validation. In the ANY.RUN sandbox session, the malware verifies the presence of a SIM card before continuing its activity. This check is commonly used to avoid execution in sandboxed or emulated environments where telephony features may be absent. After this validation, the malware proceeds with initializing its background components.

Oblivion RAT checks for a SIM card Oblivion RAT checks for a SIM card

In the observed execution, the malware establishes persistence by starting a foreground service using Android system APIs. This allows it to remain active in the background with reduced risk of being terminated by the system. Additionally, it creates a WakeLock, which prevents the device from entering sleep mode and ensures continuous execution.

WakeLock created for persistence WakeLock created for persistence

The malware demonstrates clear access to SMS data. In the analysis, it reads both the incoming messages via the SMS inbox...

The malware reads incoming SMS The malware reads incoming SMS

... and the previously sent messages via the sent folder.

The malware reads sent SMS The malware reads sent SMS

During execution, the malware generates a unique device identifier and stores it locally in shared preferences under its application directory.

Device ID created by Oblivion Device ID created by Oblivion

This identifier is then exfiltrated in two ways observed in the analysis session:

  • Sent via an HTTP POST request to a remote server;

  • Sent via SMS to a predefined phone number.

Oblivion exfiltration methods Oblivion exfiltration methods

This dual communication method suggests redundancy in ensuring the attacker receives the device registration data. After transmitting this information, the malware enters a dormant state, awaiting further instructions from its command and control infrastructure.

In parallel, the sample opens a decoy interface using a WebView, loading a legitimate-looking website (Teamo).

How Can Businesses Proactively Protect Against Oblivion RAT

Proactive defense against a threat like Oblivion RAT requires moving beyond signature-based antivirus and embracing behavior-based detection, real-time threat intelligence, and dynamic malware analysis. ANY.RUN's suite of threat intelligence solutions is specifically designed for this challenge.

Businesses can leverage ANY.RUN’s Threat Intelligence Feeds to integrate fresh IOCs (C2 IPs, hashes, domains like oblvn.sbs) directly into SIEM, TIP, or XDR solutions for real-time blocking of known Oblivion infrastructure. TI Feeds provide organizations with continuously updated streams of Indicators of Compromise (IOCs) extracted directly from millions of live malware analysis sessions conducted by a global community of over 600,000 cybersecurity professionals.

TI Feeds integrate directly into existing security infrastructure via STIX and MISP formats, with API and SDK access for SIEM, IDS/IPS, and EDR platforms.

ANY.RUN's Threat Intelligence Lookup gives security teams direct, searchable access to the full database of IOCs, TTPs, processes, files, network connections, and registry activity recorded across millions of sandbox sessions.

For deeper analysis, submit suspicious Android samples to ANY.RUN’s Interactive Sandbox to observe the full infection chain, permission abuse, and C2 callbacks in a safe environment, generating actionable reports with behavioral insights.

Oblivion TTPs mapped to MITRE ATT&CK matrix in the sandbox Oblivion TTPs mapped to MITRE ATT&CK matrix in the sandbox

Additional Measures:

  • Enforce strict mobile device management (MDM) policies prohibiting sideloading and unknown sources.

  • Deploy enterprise mobile security solutions that monitor Accessibility Service abuse.

  • Educate employees on social engineering (especially fake updates in messaging apps).

  • Keep Android OS and apps updated; use Google Play Protect and OEM security features.

  • Implement app allowlisting and regular device audits for hidden processes.

  • Monitor for anomalous SMS/notification behavior and enable MFA via authenticator apps (not SMS).

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

Oblivion RAT exemplifies the growing accessibility of advanced mobile threats through MaaS platforms. Its combination of user-friendly builders, stealthy infection, and powerful post-exploitation capabilities makes it a formidable adversary for any organization reliant on Android devices. Proactive threat intelligence, sandbox analysis, and layered defenses are essential to stay ahead of such evolving risks.

Trial TI Lookup to start gathering actionable threat intelligence on the malware that threatens your business sector and region: just sign up to ANY.RUN.

HAVE A LOOK AT

Mamba 2FA screenshot
Mamba 2FA
mamba
Mamba 2FA is an advanced phishing-as-a-service (PhaaS) platform designed to bypass multi-factor authentication (MFA) and target Microsoft 365 accounts. It focuses on intercepting authentication flows in real-time and enables threat actors to hijack user sessions and access sensitive systems even when additional security measures are in place.
Read More
AsyncRAT screenshot
AsyncRAT
asyncrat
AsyncRAT is a RAT that can monitor and remotely control infected systems. This malware was introduced on Github as a legitimate open-source remote administration software, but hackers use it for its many powerful malicious functions.
Read More
PhantomEnigma screenshot
PhantomEnigma
phantomenigma
PhantomEnigma (also known as Operation Phantom Enigma) is a sophisticated crimeware operation primarily targeting banking organizations and the public sector in Brazil. The campaign is characterized by its strategic abuse of compromised legitimate infrastructure, specifically Brazilian government (.gov.br) portals and municipal websites, to host and distribute malicious payloads.
Read More
BTMOB RAT screenshot
BTMOB RAT
btmob
BTMOB RAT is a remote access Trojan (RAT) designed to give attackers full control over infected devices. It targets Windows and Android endpoints. Its modular structure allows operators to tailor capabilities, making it suitable for espionage, credential theft, financial fraud, and establishing long-term footholds in corporate networks.
Read More
SSLoad screenshot
SSLoad
ssload
SSLoad is a malicious loader or downloader that is used to infiltrate target systems through phishing emails, perform reconnaissance and transmit it back to its operators delivering malicious payloads. To avoid detection, SSLoad employs various encryption methods and delivery techniques highlighting its versatile nature and complexity. It is believed to be a part of Malware-as-a-Service (MaaS) operation given its diverse delivery methods and implemented techniques.
Read More
Godfather screenshot
Godfather
godfather
The Godfather malware is an Android banking Trojan capable of bypassing MFA that targets mobile banking and cryptocurrency applications. Known for its ability to evade detection and mimic legitimate software, it poses a significant threat to individuals and organizations by stealing sensitive data and enabling financial fraud.
Read More