SURXRAT Android RAT — LLM Module Downloads from Hugging Face, MaaS via Telegram, ArsinkRAT Evolution — Threadlinqs Intelligence
As of 2026-05-30, SURXRAT Android RAT — LLM Module Downloads from Hugging Face, MaaS via Telegram, ArsinkRAT Evolution is a high-severity malware threat attributed to SURXRAT Operator (Indonesia), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 16 indicators of compromise.
Threat ID: TL-2026-0142 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Attribution: SURXRAT Operator · Indonesia · FINANCIAL
SURXRAT is an actively developed Android RAT commercially distributed via Telegram-based MaaS with structured reseller/partner licensing (200K-500K one-time payment). Built on ArsinkRAT code (1,216
SURXRAT is a next-generation Android Remote Access Trojan (RAT) that represents the convergence of mobile surveillance malware, AI experimentation, and commercial malware-as-a-service (MaaS) distribution. Uncovered by Cyble Research and Intelligence Labs (CRIL) in February 2026, SURXRAT has evolved from ArsinkRAT code into a feature-rich platform with novel capabilities.
The malware is marketed through a dedicated Telegram channel under the 'SURXRAT V5' branding, created in late 2024 with active development since early 2025. Over 180 related samples have been identified. The MaaS model offers two tiers: Reseller Plan (200K one-time, 3 builds/day, reselling rights) and Partner Plan (500K one-time, 10 builds/day, own reseller networks). As of January 2026, the platform reports 1,318 registered operator accounts.
SURXRAT evolved from ArsinkRAT, a cloud-native Android RAT previously tracked by Zimperium. ArsinkRAT used Firebase Realtime Database, Firebase Storage, Google Apps Script (uploading to Google Drive), and Telegram Bot API for C2/exfiltration. The predecessor campaign was massive: 1,216 unique APK hashes, 317 Firebase RTDB endpoints, and approximately 45,000 victim IPs across 143 countries. Largest victim concentrations in Egypt (~13K), Indonesia (~7K), Iraq (~3K), Yemen (~3K), and Türkiye (~2K). Distributed via Telegram, Discord, MediaFire links, impersonating 50+ brands (Google, YouTube, WhatsApp, Instagram, TikTok).
SURXRAT's key innovation is the conditional download of a large LLM module (>23GB) from Hugging Face. This download triggers when specific gaming applications are active (Free Fire MAX, Free Fire x JUJUTSU KAISEN) or when the C2 server sends target package names dynamically. The LLM module serves multiple purposes: deliberately introducing network latency during gameplay (paid cheating/disruption services), masking malicious background activity by degrading device performance, and enabling future AI-driven capabilities (automated interactions, adaptive social engineering).
The malware's C2 infrastructure uses Firebase Realtime Database (hxxps://xrat-sisuriya-default-rtdb.firebaseio[.]com) with the database reference labeled 'arsinkRAT', confirming the code lineage. Device registration uses random UUID for victim tracking.
SURXRAT provides comprehensive surveillance: SMS monitoring, contact/call log collection, Gmail account data, location tracking, notification interception, clipboard monitoring, browser history, cellular tower intelligence, WiFi scanning, file manager access. Remote control includes: device unlock, phone call initiation, wallpaper modification, audio playback, push notifications, forced URL opening, flashlight/vibration control, on-screen text overlays, and storage wipe.
The ransomware-style screen locker enables device locking with attacker-defined PIN and customizable lock message. Wrong PIN attempts are logged and transmitted to the operator in real-time. The lock can be remotely removed, giving complete control over device availability. This enables hybrid monetization: surveillance, fraud, or direct extortion based on victim value.
The Indonesian threat actor operates the platform, targeting aspiring cybercriminals rather than conducting attacks directly. The structured pricing, operational announcements, and feature updates demonstrate mature commercialization similar to underground SaaS platforms.
Weaknesses (CWE)
CWE-200, CWE-306, CWE-940
Target sectors: consumer, financial, telecommunications, gaming
Target regions: Middle East, Southeast Asia, Africa, South Asia, Europe, Americas
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 16 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1660, T1476, T1575, T1624.001, T1541, T1628.001, T1516, T1517, T1414, T1426