SyamRAT (provisional)

Malware family · 9 sample(s) · 9 indicator record(s) · 1 signing certificate(s) · Active 2026-08-21 → 2026-10-05 (experimental)

About SyamRAT (provisional)

Commodity Indonesian Android RAT distributed under utility/“booster” lures (e.g. package com.pt.sejahtera, label “pelancar hp” - Indonesian for “phone booster”). The build ships a plaintext assets/config.json naming the operator backend, and abuses AccessibilityService + MediaProjection for remote control, overlay injection and live screen capture. A bundled native module (libnuker.so / assets/nuker, an ELF) provides the screen-stream/VNC component. Live control runs over Socket.IO to the base_url in the config.

How the C2 is recovered: config.json is cleartext, so the decoder reads base_url directly (binary-verified). The webview_url (commonly https://www.google.com) and logo_url (image CDNs such as catbox.moe) are victim-facing decoys and are not recorded as C2. The operator username, session_id and per-build uid (from assets/uid.json) are captured as attribution. Family label is provisional - this is a builder kit, not a single actor.

Indicators

IndicatorTypeSampleFirst seen
syamrat.otax.fun domain 793a2cdd28f2… 2026-09-30
syamrat.otax.fun domain 68caf4b087d2… 2026-08-26
syamrat.otax.fun domain 7492ff519fbe… 2026-08-30
syamrat.otax.fun domain 984ebc258c10… 2026-08-21
syamrat.otax.fun domain aed3573f764a… 2026-09-14
syamrat.syamcloud.com domain 3efa80d2a7a1… 2026-09-29
syamrat.syamcloud.com domain 7f9d84dde2ca… 2026-10-03
syamrat.syamcloud.com domain 92e625364ce3… 2026-10-05
syamrat.syamcloud.com domain e9bf1b6ae043… 2026-09-26