AIVARAT Mobile Malware

Android 7+ Devices Become FIDO Certified

AIVARAT is the name of a newly detected strain of mobile malware. The new threat is a remote access trojan or a RAT, as the name implies.

The capabilities of the new malware are considerable. AIVARAT can scrape and exfiltrate a number of data sets from the compromised device, including system data, installed app lists, and local storage file lists. The malware can also exfiltrate any media file found on the compromised device.

AIVARAT can access call logs and contact lists on the device and can both intercept and read and send text messages. There are reports that the malware is also capable of logging keypresses on the virtual keyboard and displaying phishing screens mimicking the login interfaces of legitimate apps.

There seems to be at least some sort of persistence with the malware. While it will not run with every device boot by default, receiving any new notification will re-trigger and run it again.

The RAT also has a ransomware-like module that can encrypt files on the device and lock it with a PIN code.

July 15, 2022
Loading...

Cyclonis Backup Details & Terms

The Free Basic Cyclonis Backup plan gives you 2 GB of cloud storage space with full functionality! No credit card required. Need more storage space? Purchase a larger Cyclonis Backup plan today! To learn more about our policies and pricing, see Terms of Service, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.

Cyclonis Password Manager Details & Terms

FREE Trial: 30-Day One-Time Offer! No credit card required for Free Trial. Full functionality for the length of the Free Trial. (Full functionality after Free Trial requires subscription purchase.) To learn more about our policies and pricing, see EULA, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.