Malware

Novel Cellik Android RAT examined

Male hand holding smart phone outside.

Advanced capabilities have been touted by the newly emergent Cellix Android malware-as-a-service offering, which could be integrated into any app on the Google Play Store while allegedly evading Play Protect defenses, according to BleepingComputer.

Aside from enabling real-time screen capturing, app notification interception, file exfiltration, data wiping, and command-and-control communications, Cellik also allows payload delivery into already installed apps, as well as permits threat actors to create a trojanized version of any app of their choosing due to Play Store integration into its APK builder, a report from iVerify revealed.

"While Google Play Protect typically flags unknown or malicious apps, trojans hidden inside popular app packages might slip past automated reviews or device-level scanners," said iVerify.

With Google not yet confirming whether apps with Cellik could bypass Play Protect, Android users have been urged to refrain from sideloading APKs from suspicious sites, conduct app permission evaluations, enable Play Protect, and track for atypical activity.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

Related Terms

Adware

You can skip this ad in 5 seconds