Koktevrat Multi-Stage Android RAT Distributed via MandatGO
Score: 9/10

Koktevrat Multi-Stage Android RAT Distributed via MandatGO

Koktevrat is a multi-stage Android RAT distributed via a fake Polish government application named MandatGO that utilizes Accessibility Services and Firebase for full device control.

Executive Summary

CERT Orange Polska has identified a new multi-stage Android Remote Access Trojan (RAT) dubbed 'Koktevrat.' The malware is distributed through Facebook advertisements directing users to a phishing site (fb-market-play[.]cc) posing as 'MandatGO,' a fake Polish government application for paying fines. Koktevrat follows a multi-stage infection chain where a dropper delivers encrypted payloads (wudEMR.apk and uoN.apk), eventually deploying a full-featured RAT package.

Technically, Koktevrat relies heavily on Android's Accessibility Services (T1056.001) to perform unauthorized actions such as screen locking, keylogging, and overlay injection. It employs a hybrid C2 architecture using Firebase Cloud Messaging (FCM) for signaling and wake-up commands alongside standard HTTP C2. The malware also includes advanced features like a Domain Generation Algorithm (DGA) to rotate infrastructure and TCP tunneling to use infected devices as network proxies.

This threat is significant due to its ability to bypass standard security controls (e.g., attempting to disable Google Play Protect) and its comprehensive suite of remote control features. While functionally similar to families like FluBot or Cerberus, Koktevrat represents a distinct and sophisticated evolution in Android threat tradecraft, targeting mobile users in Poland.

Key Details

Threat Name

Koktevrat Android RAT

Affects

—

Adversary

—

Malware/Tools

koktevrat, FluBot, Cerberus, SpyNote

Report Score

9out of 10
Quality Score
Excellent
IOC Quality9
TTP Details9
Detection Guidance7
Enterprise Relevance7
Clarity & Structure10
Technical Depth9

Sources