P9A Overlay RAT (provisional)
Malware family · 1 sample(s) · 1 indicator record(s) · 1 signing certificate(s)
About P9A Overlay RAT (provisional)
P9A Overlay RAT (provisional) is a China-nexus Android Accessibility banking RAT delivered by a nested SVLT “shelltemplate” vault dropper (the vault key is carried in AndroidManifest meta-data). The child abuses Accessibility services for overlay credential theft, captures the screen via MediaProjection, uses Firebase, and talks to its operator over a WebSocket command channel at v3.p9a.xyz (endpoints /api/ws/, /gate, /api/ping). Named provisionally after its C2 domain.
Indicators
| Indicator | Type | Sample | First seen |
|---|---|---|---|
| v3.p9a.xyz | domain | 8c25e8b6bd14… | 2026-10-08 |