# cifrat — Capture Audio, Process Injection +14

Published: 2026-04-03 · Severity: medium
Canonical: https://vorant.io/reports/2ba6158b-35bb-4b74-9b31-358e764913e9/cifrat-capture-audio-process-injection-14

> CERT Polska analyzed cifrat, a multi-stage Android RAT distributed via Booking.com phishing, deploying accessibility abuse, screen streaming, and SOCKS5 tunneling.

CERT Polska identified a sophisticated Android malware campaign delivered through infrastructure impersonating Booking.com. The infection chain begins with phishing emails directing victims through Google share redirects to a fake Booking Pulse update page hosted at booking.interaction.lat. The downloaded APK (com.pulsebookmanager.helper.apk) acts as a multi-stage dropper employing native library obfuscation and anti-analysis checks. The outer APK decrypts and installs a second-stage package (io.cifnzm.utility67pu) masquerading as Google Play Services, which in turn extracts and decrypts a hidden asset (FH.svg) using RC4-like encryption keyed with 'mLYQ'. The final payload is a full-featured Android RAT communicating with otptrade.world via dual WebSocket channels.

The RAT abuses Android accessibility services to achieve extensive capabilities including screen streaming, keylogging, HTML overlay injection, SMS interception, camera access, remote gesture injection, device manipulation, and SOCKS5 proxy tunneling. The malware implements robust persistence mechanisms including uninstall protection, service health monitoring, alarm-based persistence, WebSocket recovery logic, and permission-loss protection. The dropper employs multiple anti-analysis techniques including libjdwp.so detection in /proc/self/maps, native JNI-backed string decoding with per-character XOR obfuscation, and Frida/emulator checks. Installation telemetry is exfiltrated to aplication.digital/receiving/stats. CERT Polska could not confidently attribute this malware to a known family as of the analysis date.

## Mentioned in this report

- Malware: cifrat

Source reporting: https://cert.pl/en/posts/2026/04/cifrat-analysis

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/2ba6158b-35bb-4b74-9b31-358e764913e9/cifrat-capture-audio-process-injection-14.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
