SyamRAT (provisional)
Malware family · 2 sample(s) · 2 indicator record(s) · 1 signing certificate(s)
About SyamRAT (provisional)
Commodity Indonesian Android RAT distributed under utility/“booster” lures
(e.g. package com.pt.sejahtera, label “pelancar hp” — Indonesian for “phone
booster”). The build ships a plaintext assets/config.json naming the operator
backend, and abuses AccessibilityService + MediaProjection for remote
control, overlay injection and live screen capture. A bundled native module
(libnuker.so / assets/nuker, an ELF) provides the screen-stream/VNC
component. Live control runs over Socket.IO to the base_url in the config.
How the C2 is recovered: config.json is cleartext, so the decoder reads
base_url directly (binary-verified). The webview_url (commonly
https://www.google.com) and logo_url (image CDNs such as catbox.moe) are
victim-facing decoys and are not recorded as C2. The operator username,
session_id and per-build uid (from assets/uid.json) are captured as
attribution. Family label is provisional — this is a builder kit, not a single
actor.
Indicators
| Indicator | Type | Sample | First seen |
|---|---|---|---|
| syamrat.otax.fun | domain | 793a2cdd28f2… | 2026-09-30 |
| syamrat.otax.fun | domain | 68caf4b087d2… | 2026-08-26 |