SyamRAT (provisional)

Malware family · 2 sample(s) · 2 indicator record(s) · 1 signing certificate(s)

About SyamRAT (provisional)

Commodity Indonesian Android RAT distributed under utility/“booster” lures (e.g. package com.pt.sejahtera, label “pelancar hp” — Indonesian for “phone booster”). The build ships a plaintext assets/config.json naming the operator backend, and abuses AccessibilityService + MediaProjection for remote control, overlay injection and live screen capture. A bundled native module (libnuker.so / assets/nuker, an ELF) provides the screen-stream/VNC component. Live control runs over Socket.IO to the base_url in the config.

How the C2 is recovered: config.json is cleartext, so the decoder reads base_url directly (binary-verified). The webview_url (commonly https://www.google.com) and logo_url (image CDNs such as catbox.moe) are victim-facing decoys and are not recorded as C2. The operator username, session_id and per-build uid (from assets/uid.json) are captured as attribution. Family label is provisional — this is a builder kit, not a single actor.

Indicators

IndicatorTypeSampleFirst seen
syamrat.otax.fun domain 793a2cdd28f2… 2026-09-30
syamrat.otax.fun domain 68caf4b087d2… 2026-08-26