{
  "family": "rvrat",
  "sample_count": 1,
  "category": "trojan",
  "description": "<h3>Executive Summary</h3>\nRvRAT is a highly capable Remote Access Trojan (RAT) engineered to provide attackers with covert, persistent, and fully interactive control over compromised endpoints. While variants exist for Windows, RvRAT is particularly noted for its presence in the mobile threat landscape, frequently targeting Android devices to facilitate deep surveillance and data exfiltration.\n\n<h3>Infection Vector and Technical Capabilities</h3>\nOn Windows, RvRAT is primarily distributed via spear-phishing campaigns utilizing weaponized attachments. On Android, it is typically distributed via malicious APKs disguised as legitimate applications (e.g., fake system updates or popular games) hosted on third-party app stores or delivered via SMS phishing (smishing).\n\nOnce executed, RvRAT focuses on establishing a deep, persistent foothold:\n<ul>\n<li><strong>Covert C2 Communication:</strong> The RAT establishes a persistent connection to its command-and-control (C2) server. It frequently utilizes encrypted communications and may rely on dynamic DNS (DDNS) services to shift its infrastructure.</li>\n<li><strong>Comprehensive Espionage (Mobile & Desktop):</strong> RvRAT provides the attacker with a vast array of surveillance capabilities. This includes real-time location tracking (GPS), SMS and call log interception, file system manipulation, keylogging, and the ability to silently activate connected webcams or microphones for live surveillance.</li>\n<li><strong>Credential Harvesting:</strong> A primary objective is credential theft. The RAT actively scans for and extracts saved passwords from web browsers, cryptocurrency wallet apps, and secure enclaves.</li>\n</ul>\n\n<h3>Threat Assessment</h3>\nAn RvRAT infection is a critical security incident. The malware's extensive capabilities mean that the compromised endpoint (whether a corporate workstation or a BYOD mobile device) is fully under the control of the attacker, leading to the immediate loss of intellectual property and compromised user credentials.\n\n<h3>Incident Response and Remediation</h3>\n<ul>\n<li><strong>Immediate Isolation:</strong> Sever the affected machine's (or mobile device's) network connection immediately to halt the C2 communication and prevent active data exfiltration.</li>\n<li><strong>Device Wipe (Mobile):</strong> For compromised Android devices, attempting to uninstall the malicious app is often insufficient due to privilege escalation. A complete factory reset is the recommended remediation.</li>\n<li><strong>Comprehensive Credential Reset:</strong> Assume all credentials utilized on the infected machine or mobile device, as well as any stored in browsers or password managers, are fully compromised. Initiate an immediate, organization-wide password reset.</li>\n</ul>",
  "cta": "Published by the SystemHelpdesk team.",
  "aliases": [
    "Trojan.RvRAT",
    "Android.RvRAT",
    "Backdoor.RvRAT"
  ],
  "enrichment_level": "insufficient_information",
  "faq": [],
  "faq_count": 0,
  "mitre_attack": [
    "T1059",
    "T1056.001",
    "T1113",
    "T1437"
  ],
  "cisa_advisory": null,
  "last_updated": "2026-07-01T16:44:41Z",
  "type": "RAT",
  "target_industries": [
    "Global / Opportunistic"
  ],
  "motivation": "Opportunistic",
  "threat_actors": [
    "Unknown / Cybercriminal"
  ],
  "target_geographies": [
    "Global"
  ]
}