| Facebook: | | Telegram: Join @fztvseries | Instagram: Follow @fztvseries |
| Facebook: | | Telegram: Join @fztvseries | Instagram: Follow @fztvseries |
Request TvShows or Report error with existing ones, Email us at [email protected]: Unmasking EVLF DEV - The Creator of CypherRAT and CraxsRAT The Hacker News Summary : Syrian Threat Actor EVLF Unmasked
Through these operations, EVLF DEV generated an estimated by hosting a surface-web store. He sold lifetime malware licenses to over 100 unique threat groups globally before eventually announcing a cessation of official support for the tools. 🛠️ Deep Dive: The Core Capabilities of Cypher Rat
However, the structure of the keyword suggests a few possibilities: it could be a typo, a niche inside joke, an obscure username, a fragment of a cipher key, or a low-competition term artificially constructed for SEO testing. Cypher Rat Evlf
: Analysis of hardening techniques used in CraxsRAT/CypherRAT variants can also be found on Medium .
The malware can steal contacts, read and delete SMS messages, and access call logs and external storage. : Unmasking EVLF DEV - The Creator of
To bypass modern Android security restrictions, both malware families heavily targeted the framework. During the installation process, the malware prompted users to grant accessibility permissions. Once approved, the software gained the ability to autonomously read text displayed on the screen, simulate user touches, log keystrokes, and interact with applications without user intervention. The "Super Mod" Persistence Feature
Cypher RAT is built to strip away a user's privacy and compromise corporate endpoints through structural control over the Android OS framework. When compiled using EVLF's customized execution builders, the malware gains a suite of surveillance and data exfiltration abilities: During the installation process, the malware prompted users
In mid-2023, deep operational security failures by EVLF allowed threat intelligence analysts to fully map the threat actor's infrastructure. By tracking cryptocurrency financial records posted on open Web3 discussion forums, researchers discovered active links to private communication platforms, email accounts, and a specific IP range. The investigation ultimately revealed the developer's suspected identity as a Syrian national.
Screen viewing/control, keystroke logging (keylogger), and the ability to download/install additional APKs.