888 RAT

First seen
2018-01-01 00:00:00
Malware type
rat, spyware, credential-stealer, screen-capture
Family
Malware family
Last IoC activity
2026-07-22 02:45:08
Profile updated
2026-07-07 13:00:53

Targeted industries: government-and-public-sector financial-services technology-and-telecommunications

Context

According to ESET, this is a commercial, multiplatform RAT, originally developed for Windows and extended to Android. In short, it can steal and delete files from a device, take screenshots, get device location, phish Facebook credentials, get a list of installed apps, steal user photos, take photos, record surrounding audio and phone calls, make calls, steal SMS messages, steal the device’s contact list, send text messages, etc.

Reports & references

  • ESET — Bladehawk Android Espionage Kurdish (report)
  • malpedia.caad.fkie.fraunhofer.de — Apk.888 Rat (report)

External references