KsRemote

Description

(Malwarebytes) We also found several malicious Android applications we believe are part of the toolset used by this APT group. Malwarebytes detects them as Android/Trojan.Spy.AndroRat.KSRemote.

All these bogus applications contain a jar file named ksremote.jar that provides the RAT functionality: • Recording screen and audio using the phone’ss camera/mic • Locating phone with coordinates • Stealing phone contacts, call log, SMS, web history • Sending SMS messages

Names

Name
KsRemote

Category

Malware

Type

  • Backdoor
  • Info stealer
  • Exfiltration

Information

Malpedia

Other Information

Uuid

3eb1ad56-859e-41ef-b3c7-e5474133fce0

Last Card Change

2021-08-10