RatHat FRP-tunneled C2 exfiltration API traffic (SMS/creds/files/screen)
Detects network activity associated with the RatHat Android malware, specifically identifying C2 data exfiltration API calls over FRP (FRP/Go Agent) tunnels and WebSocket handshake traffic for command-and-control communication.
Suricata

