
CraxsRAT is a commercially sold Android Remote Access Trojan that grants attackers extensive control over infected devices. Recent campaigns observed in the region distribute it through malicious APKs disguised as legitimate apps and banking utilities.
Once installed, the malware abuses Android Accessibility Services to capture keystrokes, read on-screen content, intercept one-time passwords, and even perform actions on the victim's behalf. This makes it especially dangerous for mobile banking users.
To stay protected, only install apps from official stores, scrutinize permission requests—especially Accessibility access—and keep your device updated. Enterprises should enforce mobile device management and educate staff about the risks of side-loading.
Our threat intelligence and managed security services help organizations detect and respond to mobile threats like CraxsRAT before they cause financial or reputational damage.


