Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Oblivion RAT

113
Global rank
117 infographic chevron month
Month rank
198 infographic chevron week
Week rank
0
IOCs

Oblivion RAT is a sophisticated Android Remote Access Trojan (RAT) offered as Malware-as-a-Service (MaaS) on cybercrime forums for as little as $300 per month. It equips even novice attackers with a complete toolkit, including a web-based APK builder, dropper generator mimicking Google Play updates, and a real-time C2 panel. The RAT enables full device takeover, data theft, and financial fraud through deceptive social engineering and Accessibility Service abuse.

RAT
Type
Unknown
Origin
1 February, 2026
First seen
27 August, 2026
Last seen

How to analyze Oblivion RAT with ANY.RUN

RAT
Type
Unknown
Origin
1 February, 2026
First seen
27 August, 2026
Last seen

IOCs

IP addresses
216.239.35.8
142.250.154.113
142.251.127.81
216.239.35.12
216.239.35.0
142.251.151.119
216.239.35.4
142.251.110.94
142.251.150.119
142.251.13.113
142.251.153.119
45.11.37.254
142.251.110.100
142.251.14.100
34.104.35.123
142.250.154.94
142.251.156.119
142.251.13.101
142.251.13.94
142.251.157.119
Hashes
1005a525006f148c86efcbfb36c6eac091b311532448010f70f7de9a68007167
fbcfe23a2ecb82b7100c50811691dde0a33aa3da8d176be9882a9db485dc0f2d
0f1bad70c7bd1e0a69562853ec529355462fcd0423263a3d39d6d0d70b780443
3b9d18d5cc3af6c0cb3e903327ae3da35634c7c3a0b11413b9a3b1c10c640d5e
6299022fc72776796da52158384714122b6ef0f7495e26756b0c868a149e3412
70cfc2370ec708ae9a865a3b8f3cc543c59042c6d8d1a266c583583d33765260
220601515eeeef3c03cebae7e89f8018a86503a78cda58eaf499cef02d44c78f
cea7d219ef64afebfd04ba87827cbc7596c2ec869edbc5297ee49fe282f14512
d74788e6c8040c026338d616db79a9e93dea0750e274f858e7fcfbdac4a03759
fc08576860919d81bfbc4acbf32e765dbd9956a9a274e771de4a6149f320e8db
a24fcf8df3dce84fd85648180bc002e478b19f9afce640dc14b55ce24d4a5394
f283c13f185ce3abea16da804acd9aae30dd103ffe37c0325ba9cbb03d5624e3
b8f403cee06556a78e1b18466fe207b323e13da185fcca91b46c488fbc88fa87
bb9f8df61474d25e71fa00722318cd387396ca1736605e1248821cc0de3d3af8
f9d31b278e215eb0d0e9cd709edfa037e828f36214ab7906f612160fead4b2b4
8e89bbb65cdd9fffc294660ba897eb044424a9f80306f1f1f165aeea01d9b8ec
8582a0494656ad4d7e3102f09e37bf6e9bd196c3470a9d54bfebd48462e78a08
cd1dc6808aa0592d53739604d8e74c118f50fd0d8d1e27a29a4d4f708cacb70c
f885e20806e8528b7c00a0f770b32faff4ac7b0f2603aa1891758d5fe8b7a5fe
71bdf5dc7eab3dc596af69a92d8886b6c8358ddd38d6aa2980b04826a213f916
Domains
google.com
update.googleapis.com
connectivitycheck.gstatic.com
time.android.com
www.google.com
clientservices.googleapis.com
staging-remoteprovisioning.sandbox.googleapis.com
s3.eu-central-003.backblazeb2.com
edgedl.me.gvt1.com
play.googleapis.com
static.apkpures.xyz
googleads.g.doubleclick.net
cdn.mediago.io
r.cdnpure.com
a.apkpures.xyz
trace-eu.mediago.io
ampcid.google.it
udbdf.apkpure.com
static.admaster.cc
static.apkpure.com
URLs
http://connectivitycheck.gstatic.com/generate_204
https://www.google.com/generate_204
https://staging-remoteprovisioning.sandbox.googleapis.com/v1:fetcheekchain
https://clientservices.googleapis.com/chrome-variations/seed?osname=android_webview&milestone=137
https://update.googleapis.com/service/update2/json?cup2key=15:suh4psyzzelcn-q9tn-stroyneqj5pndmfqtwhs_arq&cup2hreq=31917312c2dfe422fd29a42296a7d835ba38fa38fd1f4977feac7eb82271cd1a
https://s3.eu-central-003.backblazeb2.com/edgecdn-k7m2qx/172e5a4f627ebe3d.bin
https://staging-remoteprovisioning.sandbox.googleapis.com/v1:signcertificates?challenge=aaaboc0nuiqbilsty5ubdcfqrzev6oi_h2prfxa=&request_id=912eef10-51b5-4b8a-b7de-f9fcd487b7e1
https://update.googleapis.com/service/update2/json?cup2key=15:auw1kvc_cwjezxmkugrauyc7oeijpjxjitul-bfcnq4&cup2hreq=47154da86e116b120ddc918c71618eaccd5f71410c9eb1f813ab529780abbc95
https://update.googleapis.com/service/update2/json
https://edgedl.me.gvt1.com/edgedl/release2/chrome_component/acmmwq7dser4xm5sepzjv74g65vq_2023.7.28.10/cffplpkejcbdpfnfabnjikeicbedmifn_2023.07.28.10_all_acgbwixmcanakp2bkoppyszsbkrq.crx3
http://play.googleapis.com/generate_204
https://update.googleapis.com/service/update2/json?cup2key=15:n91pksr8zlxv-he0dqu-pnsmlnbip-v8mzit0ana81w&cup2hreq=7191f1f5270c9ca5860ce94a7738938052b19b604812648a443823beccf0032b
http://www.google.com/gen_204
http://193.111.117.72:8080/ping
https://staging-remoteprovisioning.sandbox.googleapis.com/v1:signcertificates?challenge=aaabocngx1obilsty-ytcg2bvrdyhfdfo-wbhfw=&request_id=e078412c-b726-46f8-9982-3c02f43fdcb9
https://update.googleapis.com/service/update2/json?cup2key=15:rnqmivzys0b1boqbwmj4knb73oi_wa5m8zikfl8anks&cup2hreq=53cdedb6d60e217285025b820be78f83861ec834c4a854d80d103fee4a7ecdd5
https://staging-remoteprovisioning.sandbox.googleapis.com/v1:signcertificates?challenge=aaaboa_2zbybilsty9epugtk1ztoglrwb4accng=&request_id=7e73ffed-a311-42fc-86e1-b97cabf8c4b0
https://update.googleapis.com/service/update2/json?cup2key=15:qmyc-cpbsrof8yf5tqlc0b2eebtyn-6w6zlrimdnww8&cup2hreq=29421d2f45f92d82623855883a86ad60db4971e59aaa2f85a8ca2820469361cf
https://m.apkpure.com/ru/stalkgram/com.adriva.whatsupp/download/1.21
https://m.apkpure.com/language_v1034.js?hl=ru-ru
Last Seen at

Recent blog posts

post image
ANY.RUN Secures Leader Status in G2’s Malware...
watchers 3987
comments 0
post image
15 Minutes Saved Per Alert: How a Lean German...
watchers 8278
comments 0
post image
HVNC Backdoor Targets LATAM Organizations wit...
watchers 10341
comments 0

Fake Updates, Real Takeover: Inside Oblivion RAT’s Stealthy Assault on Android Devices

Key Takeaways

  1. Oblivion RAT is a new Android MaaS RAT sold for $300/month with built-in APK and dropper builders for easy deployment.

  2. It uses fake Google Play update pages and Accessibility Service abuse for silent, permissionless installation.

  3. Core features include hidden VNC control, SMS/2FA interception, keylogging, and “Wealth Assessment” for targeting financial apps.

  4. Businesses face risks of data theft, fraud, and compliance breaches, especially in finance, defense, and mobile-heavy sectors.

  5. The threat has already infected over 7,500 devices since early 2026, with campaigns scaling rapidly via social engineering.

  6. Use ANY.RUN TI Lookup to hunt Oblivion proactively: search IOCs and enrich investigations instantly to block emerging variants before they strike.

destinationIP:"193.221.200.242".

Malicious IP linked to Oblivion RAT Malicious IP linked to Oblivion RAT

  1. Analyze suspicious Android files in ANY.RUN’s Interactive Sandbox for interactive, real-time visibility into RAT behavior and full threat context.

View analysis session

Oblivion RAT analysis in Interactive Sandbox Oblivion RAT fresh sample analysis in Interactive Sandbox

What is Oblivion RAT Malware?

Oblivion RAT is a newly emerged Android Remote Access Trojan (RAT) sold as a Malware-as-a-Service (MaaS) platform on underground cybercrime forums first publicly reported in February 2026. For a subscription starting at $300 per month, any would-be attacker gains access to a toolkit capable of silently hijacking nearly every Android device in active use today, no coding skills required.

The platform targets Android versions 8 through 16, covering virtually the entire active Android install base. Its combination of automated permission bypass, a Hidden VNC remote control channel, real-time OTP interception, and deep anti-removal persistence makes it one of the most capable and accessible mobile threats observed to date.

The platform consists of three core components that work in concert: a web-based APK Builder, a Dropper Builder, and a real-time command-and-control (C2) panel. Together these tools allow operators to build customized malware, deploy it convincingly to victims, and then manage hundreds of compromised devices through a single dashboard.

The APK Builder lets operators configure the malicious app's name, icon, and package name through a web interface. Two deployment modes are available. In stealth mode, the installed app immediately requests Accessibility Service permissions in the background, hides its icon from the home screen, and shows no visible interface at all.

In webview mode, the app opens a legitimate-looking website as a decoy while silently acquiring the same permissions behind the scenes. Default package name patterns (com.darkpurecore* for the dropper, net.darkhyperapps* for the implant) are visible across analyzed samples, providing a valuable detection foothold for defenders.

The Dropper Builder generates pixel-perfect imitations of the Google Play Store update flow. Victims are walked through three convincing pages: a fake download progress bar with a simulated security scan, a counterfeit Play Store listing complete with a developer name of 'LLC Google,' a 4.5-star rating, and an Update button, and finally a step-by-step guide framing sideloading as 'a standard security procedure.' All three pages auto-translate into the target's language, with confirmed presets for English and Russian.

On the technical side, Oblivion uses several anti-analysis techniques. Its most notable trick is a 'fake ZIP encryption' flag embedded in the APK that causes standard reverse-engineering tools like jadx and apktool to halt and report the file as encrypted. In reality, the contents are ordinarily compressed and can be extracted manually.

The malware's C2 configuration is stored as a plaintext Base64 string without meaningful encryption, inadvertently exposing critical infrastructure details including the C2 server address and operator authentication tokens prefixed with 'OBL_'. C2 communication runs over self-signed TLS with the Common Name set to 'OblivionServer,' another detection-friendly indicator.

How Oblivion RAT Threatens Businesses and Organizations

Oblivion RAT poses a severe risk to enterprises by turning employee or contractor Android devices into persistent surveillance and fraud tools. It silently intercepts SMS-based 2FA codes, push notifications (including from corporate banking or email apps), keystrokes, contacts, call logs, GPS location, and files. In a BYOD or mobile-first environment, this enables credential theft for corporate accounts, data exfiltration, and even remote app control that could compromise internal systems.

The “Wealth Assessment” feature specifically flags financial apps, making it ideal for targeted business email compromise or account takeover fraud. Organizations face regulatory risks (e.g., GDPR, CCPA violations from stolen personal data), financial losses from fraud, and reputational damage. Its ability to bypass Google Play Protect (with some samples showing low detection rates) and major OEM security layers amplifies the threat to mobile endpoints, which are often the weakest link in corporate defenses.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

Victimology: Which Industries Are Most at Risk?

While public data on specific victims remains limited due to the malware’s recency, Oblivion RAT’s design points to broad targeting via social engineering on messaging and dating apps. Over 7,500 infected devices have been observed globally since early 2026, with campaigns lasting an average of 21 days.

Potentially High-Risk Sectors:

  • Financial Services & Fintech: Wealth Assessment prioritizes banking/crypto apps; SMS/2FA interception enables account takeovers.

  • Defense, Media & Tech Research: Reported targeting in some campaigns; access to sensitive communications and location data.

  • Healthcare & Government: Mobile workforce handling sensitive data; potential for notification interception and surveillance.

  • Any Enterprise with BYOD/Mobile Workforce: High exposure via sideloaded apps; persistence on employee devices accessing corporate resources.

According to ANY.RUN threat intelligence data, the most recent Oblivion campaigns have been targeting IT, Telecom and Healthcare companies:

threatName:"oblivion".

Industries targeted by Oblivion RAT Industries targeted by Oblivion RAT

Oblivion's MaaS business model means attackers do not need specialized knowledge of any one sector. The Wealth Assessment module performs automatic target prioritization, the platform itself identifies which victims are most financially valuable. Organizations in any sector with employees using Android devices for work or authentication are within scope.

How Does Oblivion RAT Get In the System and Spread?

Oblivion employs a two-stage infection chain initiated through targeted social engineering:

1. Dropper Stage: Distributed via messaging/dating apps. The dropper APK contains a compressed payload and three embedded HTML pages mimicking Google Play update flows (progress bar, fake “LLC Google” listing, sideloading instructions). It tricks users into enabling unknown sources and installing the implant.

2. Implant Stage: The payload uses a fake Accessibility Service settings screen to gain control. Once enabled, it auto-grants permissions (SMS, notifications, storage, device admin) invisibly and hides all dialogs.

Key Spread Vectors: Phishing links in chats, fake app updates. No email or drive-by downloads reported, purely user-assisted sideloaded APKs. Persistence via boot receiver and anti-removal hooks ensures long-term access.

How Does Oblivion RAT Malware Function?

After installation:

  • Permission Escalation & Stealth: Abuses Accessibility Service for UI automation, keylogging, and dialog suppression. Hides icon and processes; blocks removal attempts.

  • Remote Control: Full HVNC with MediaProjection for touch input; victims see fake overlays while attackers interact live. Includes Screen Reader mode for banking apps.

  • Data Exfiltration: Intercepts SMS/OTP/2FA, notifications, keystrokes (timestamped by app), contacts, calls, location, files. Wealth Assessment scans apps for financial targeting.

  • C2 Communication: Self-signed TLS to IPs like 89.125.48.159:8888; config in plaintext base64.

  • Anti-Analysis: Fake ZIP encryption flag (bit 0x0809) fools tools like apktool/jadx.

Oblivion capabilities and commands Oblivion capabilities and commands

Sandbox Analysis of Oblivion Sample

See the detonation of Oblivion

Oblivion RAT in action in the sandbox Oblivion RAT in action in the sandbox

The analyzed sample of Oblivion RAT begins execution by performing basic environment validation. In the ANY.RUN sandbox session, the malware verifies the presence of a SIM card before continuing its activity. This check is commonly used to avoid execution in sandboxed or emulated environments where telephony features may be absent. After this validation, the malware proceeds with initializing its background components.

Oblivion RAT checks for a SIM card Oblivion RAT checks for a SIM card

In the observed execution, the malware establishes persistence by starting a foreground service using Android system APIs. This allows it to remain active in the background with reduced risk of being terminated by the system. Additionally, it creates a WakeLock, which prevents the device from entering sleep mode and ensures continuous execution.

WakeLock created for persistence WakeLock created for persistence

The malware demonstrates clear access to SMS data. In the analysis, it reads both the incoming messages via the SMS inbox...

The malware reads incoming SMS The malware reads incoming SMS

... and the previously sent messages via the sent folder.

The malware reads sent SMS The malware reads sent SMS

During execution, the malware generates a unique device identifier and stores it locally in shared preferences under its application directory.

Device ID created by Oblivion Device ID created by Oblivion

This identifier is then exfiltrated in two ways observed in the analysis session:

  • Sent via an HTTP POST request to a remote server;

  • Sent via SMS to a predefined phone number.

Oblivion exfiltration methods Oblivion exfiltration methods

This dual communication method suggests redundancy in ensuring the attacker receives the device registration data. After transmitting this information, the malware enters a dormant state, awaiting further instructions from its command and control infrastructure.

In parallel, the sample opens a decoy interface using a WebView, loading a legitimate-looking website (Teamo).

How Can Businesses Proactively Protect Against Oblivion RAT

Proactive defense against a threat like Oblivion RAT requires moving beyond signature-based antivirus and embracing behavior-based detection, real-time threat intelligence, and dynamic malware analysis. ANY.RUN's suite of threat intelligence solutions is specifically designed for this challenge.

Businesses can leverage ANY.RUN’s Threat Intelligence Feeds to integrate fresh IOCs (C2 IPs, hashes, domains like oblvn.sbs) directly into SIEM, TIP, or XDR solutions for real-time blocking of known Oblivion infrastructure. TI Feeds provide organizations with continuously updated streams of Indicators of Compromise (IOCs) extracted directly from millions of live malware analysis sessions conducted by a global community of over 600,000 cybersecurity professionals.

TI Feeds integrate directly into existing security infrastructure via STIX and MISP formats, with API and SDK access for SIEM, IDS/IPS, and EDR platforms.

ANY.RUN's Threat Intelligence Lookup gives security teams direct, searchable access to the full database of IOCs, TTPs, processes, files, network connections, and registry activity recorded across millions of sandbox sessions.

For deeper analysis, submit suspicious Android samples to ANY.RUN’s Interactive Sandbox to observe the full infection chain, permission abuse, and C2 callbacks in a safe environment, generating actionable reports with behavioral insights.

Oblivion TTPs mapped to MITRE ATT&CK matrix in the sandbox Oblivion TTPs mapped to MITRE ATT&CK matrix in the sandbox

Additional Measures:

  • Enforce strict mobile device management (MDM) policies prohibiting sideloading and unknown sources.

  • Deploy enterprise mobile security solutions that monitor Accessibility Service abuse.

  • Educate employees on social engineering (especially fake updates in messaging apps).

  • Keep Android OS and apps updated; use Google Play Protect and OEM security features.

  • Implement app allowlisting and regular device audits for hidden processes.

  • Monitor for anomalous SMS/notification behavior and enable MFA via authenticator apps (not SMS).

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

Oblivion RAT exemplifies the growing accessibility of advanced mobile threats through MaaS platforms. Its combination of user-friendly builders, stealthy infection, and powerful post-exploitation capabilities makes it a formidable adversary for any organization reliant on Android devices. Proactive threat intelligence, sandbox analysis, and layered defenses are essential to stay ahead of such evolving risks.

Trial TI Lookup to start gathering actionable threat intelligence on the malware that threatens your business sector and region: just sign up to ANY.RUN.

HAVE A LOOK AT

Pulsar RAT screenshot
Pulsar RAT
pulsar
Pulsar RAT is a derivative of Quasar RAT with extensive functionality including keylogging, cryptocurrency wallet clipping, credential theft, file management, remote shell execution, and data exfiltration capabilities. As a modular, open-source remote administration tool designed for Windows systems, Pulsar introduces significant enhancements over its predecessor.
Read More
DarkComet screenshot
DarkComet
darkcomet rat darkcomet rat
DarkComet RAT is a malicious program designed to remotely control or administer a victim's computer, steal private data and spy on the victim.
Read More
Remote Access Trojan screenshot
Remote access trojans (RATs) are a type of malware that enables attackers to establish complete to partial control over infected computers. Such malicious programs often have a modular design, offering a wide range of functionalities for conducting illicit activities on compromised systems. Some of the most common features of RATs include access to the users’ data, webcam, and keystrokes. This malware is often distributed through phishing emails and links.
Read More
EvilTokens screenshot
EvilTokens
eviltokens
EvilTokens is a phishing-as-a-service (PhaaS) toolkit that emerged in mid-February 2026. It automates device code phishing attacks against Microsoft 365 and Entra ID environments. Unlike traditional credential-harvesting phishing, EvilTokens tricks users into completing legitimate authentication on Microsoft's own login pages, resulting in the issuance of valid OAuth access and refresh tokens directly to the attacker, effectively bypassing MFA without stealing passwords.
Read More
AsyncRAT screenshot
AsyncRAT
asyncrat
AsyncRAT is a RAT that can monitor and remotely control infected systems. This malware was introduced on Github as a legitimate open-source remote administration software, but hackers use it for its many powerful malicious functions.
Read More
DEVMAN screenshot
DEVMAN
devman
DEVMAN is a fast-evolving malware family targeting Windows environments with a mix of credential theft, remote control capabilities, and persistence techniques typical of modern crimeware. Initially observed in early 2025, DEVMAN quickly became a favorite tool among cybercriminal groups thanks to its stealth, modular structure, and ability to bypass traditional AV solutions.
Read More