ThreatFabric says the Android spyware encrypts stolen data and relays it over Wi-Fi Direct and Bluetooth when it cannot reach its C2, using up to four hops by default.
Perspective Coverage
4 publishers
- Builder
- Builder 36%
- Operator
- Operator 58%
- Investor
- Investor 6%
Reality
- Evidence65
- Adoption
- Insufficient
- Hype gap+20
- Incentives35
- Confidence68
ThreatFabric traced the StreamRat dropper through four ordinary Android permission prompts to an Accessibility grant that hands operators keystrokes, credential overlays and remote control, with no infection count published.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+15
- Incentives40
- Confidence60
The Georgia Tech corpus says the handset belongs to the attacker while Regulation E says the loss belongs to the bank, which makes every extra authentication factor pushed to that same phone a purchase with no yield.
Reality
- Evidence72
- Adoption68
- Hype gap+12
- Incentives66
- Confidence60
ThreatFabric says the Android trojan hands collected data to nearby infected devices over Wi-Fi Direct or Bluetooth until one can reach command and control.
Reality
- Evidence48
- Adoption40
- Hype gap+18
- Incentives70
- Confidence52
ThreatFabric says the Android malware encrypts what it steals and passes it over Wi-Fi Direct and Bluetooth until it reaches an infected device that is online. Network egress control never sees it.
Reality
- Evidence44
- Adoption
- Insufficient
- Hype gap+26
- Incentives58
- Confidence41