MMRat

Malware family · 5 sample(s) · 5 indicator record(s) · 1 signing certificate(s)

About MMRat

Android banking trojan carrying out bank fraud via fake app stores, abusing the RTSP stack for its C2 channel: the endpoints are rtsp:// const-strings in the <init> of the short helper classes under com/mm/user/utils/. Identified by the com.mm.user.ui.activity.WebViewActivity activity.

Indicators

IndicatorTypeSampleFirst seen
202.95.15.135:8554/live/display/ ip d06fc998c4aa… 2023-08-07
202.95.15.135:8554/live/display/ ip 124d3a55770d… 2023-09-03
202.95.15.135:8554/live/display/ ip 51847406cf99… 2023-07-26
27.124.3.165:8554/live/ ip 68abbf83f53f… 2023-06-19
45.61.128.113:8554/live/display/ ip ac2f69c3b940… 2023-08-07