Executive Summary
CERT Orange Polska has identified a new multi-stage Android Remote Access Trojan (RAT) dubbed 'Koktevrat.' The malware is distributed through Facebook advertisements directing users to a phishing site (fb-market-play[.]cc) posing as 'MandatGO,' a fake Polish government application for paying fines. Koktevrat follows a multi-stage infection chain where a dropper delivers encrypted payloads (wudEMR.apk and uoN.apk), eventually deploying a full-featured RAT package.
Technically, Koktevrat relies heavily on Android's Accessibility Services (T1056.001) to perform unauthorized actions such as screen locking, keylogging, and overlay injection. It employs a hybrid C2 architecture using Firebase Cloud Messaging (FCM) for signaling and wake-up commands alongside standard HTTP C2. The malware also includes advanced features like a Domain Generation Algorithm (DGA) to rotate infrastructure and TCP tunneling to use infected devices as network proxies.
This threat is significant due to its ability to bypass standard security controls (e.g., attempting to disable Google Play Protect) and its comprehensive suite of remote control features. While functionally similar to families like FluBot or Cerberus, Koktevrat represents a distinct and sophisticated evolution in Android threat tradecraft, targeting mobile users in Poland.
