Go to listing page

EVLF DEV - Knowing the Creator of CypherRAT and CraxsRAT

EVLF DEV - Knowing the Creator of CypherRAT and CraxsRAT
There’s a new Malware-as-a-Service (MaaS) operator in cyber threat town, named EVLF DEV. This threat actor is responsible for creating the CypherRAT and CraxsRAT malware, which have been purchased by over 100 threat actors. EVLF has been operating from Syria for over 8 years and has amassed $75,000 through the sale of these RATs.

Diving into details

  • For the last three years, EVLF has been providing CraxsRAT through an online store on a surface web store. Perceived as one of the most dangerous Android RATs currently available, actors have sold at least 100-lifetime licenses for CraxsRAT so far.
  • CraxsRAT builder is responsible for crafting heavily obfuscated packages, enabling malicious actors to customize the contents based on the specific nature of the attack they are planning, including the implementation of WebView page injections.
  • When activated on compromised devices, the RAT is capable of retrieving accurate device location, pilfering contact information, gaining access to the device's storage, and extracting message and call log data.

The researchers uncovered that the threat actor has been using a widely recognized cryptocurrency wallet for a minimum of the past three years to withdraw profits earned from vending CypherRAT and CraxsRAT.

MaaS offerings in vogue

  • In June, DogeRAT, an Android malware was found targeting various industries, including banking and gaming. The developers of DogeRAT, suspected to be from India, promoted it as a MaaS offering. This open-source malware not only acts as a remote access tool but also functions as a keylogger and can copy content from the clipboard.
  • April witnessed the emergence of a new MaaS operator, FusionCore, that also created a ransomware affiliate program called AnthraXXXLocker. The threat actor offers various custom malware, including ransomware, infostealers, and cryptocurrency mining tools.

The bottom line

The rise of MaaS operators such as EVLF DEV underlines the concerning trend of cyber threats evolving into profitable enterprises. To counteract such campaigns by malicious actors, individuals should practice caution while downloading applications, refrain from interacting with dubious links or attachments, and limit app installations to authorized stores.
Cyware Publisher

Publisher

Cyware