VORANT. Threat Intelligence Sign in Get the full feed

cifrat — Capture Audio, Process Injection +14

medium threat

CERT Polska analyzed cifrat, a multi-stage Android RAT distributed via Booking.com phishing, deploying accessibility abuse, screen streaming, and SOCKS5 tunneling.

CERT Polska identified a sophisticated Android malware campaign delivered through infrastructure impersonating Booking.com. The infection chain begins with phishing emails directing victims through Google share redirects to a fake Booking Pulse update page hosted at booking.interaction.lat. The downloaded APK (com.pulsebookmanager.helper.apk) acts as a multi-stage dropper employing native library obfuscation and anti-analysis checks. The outer APK decrypts and installs a second-stage package (io.cifnzm.utility67pu) masquerading as Google Play Services, which in turn extracts and decrypts a hidden asset (FH.svg) using RC4-like encryption keyed with 'mLYQ'. The final payload is a full-featured Android RAT communicating with otptrade.world via dual WebSocket channels.

The RAT abuses Android accessibility services to achieve extensive capabilities including screen streaming, keylogging, HTML overlay injection, SMS interception, camera access, remote gesture injection, device manipulation, and SOCKS5 proxy tunneling. The malware implements robust persistence mechanisms including uninstall protection, service health monitoring, alarm-based persistence, WebSocket recovery logic, and permission-loss protection. The dropper employs multiple anti-analysis techniques including libjdwp.so detection in /proc/self/maps, native JNI-backed string decoding with per-character XOR obfuscation, and Frida/emulator checks. Installation telemetry is exfiltrated to aplication.digital/receiving/stats. CERT Polska could not confidently attribute this malware to a known family as of the analysis date.

Mentioned in this report

Malware cifrat

Source reporting: https://cert.pl/en/posts/2026/04/cifrat-analysis

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free