SURXRAT Android RAT — LLM Module Downloads from Hugging Face, MaaS via Telegram, ArsinkRAT Evolution
SURXRAT Android RAT (TL-2026-0142), also tracked as SURXRAT, is a high-severity malware campaign, first published 2026-02-24. It is attributed to SURXRAT Operator (Indonesia) with medium confidence, affects Google Android, maps to 26 MITRE ATT&CK techniques (T1414, T1420, T1422), and is covered by 9 detection rules and 16 indicators of compromise.
Key facts for TL-2026-0142
- Threat ID
- TL-2026-0142
- Also known as
- SURXRAT, SURXRAT V5, ArsinkRAT
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- 2026-02-24
- Last reviewed
- 2026-02-24
- Attribution
- SURXRAT Operator
- Attribution confidence
- MEDIUM
- Nation-state nexus
- Indonesia
- Motivation
- FINANCIAL
- Target sectors
- consumer, financial, telecommunications, gaming
- Target regions
- Middle East, Southeast Asia, Africa, South Asia, Europe, Americas
- Detection rules
- 9
- Indicators of compromise
- 16
Malware and tooling in SURXRAT Android RAT
Malware and tooling: SURXRAT
SURXRAT is an actively developed Android RAT commercially distributed via Telegram-based MaaS with structured reseller/partner licensing (200K-500K one-time payment). Built on ArsinkRAT code (1,216 APK hashes, 317 Firebase C2 endpoints, 45,000 victims across 143 countries), SURXRAT V5 operates as a full surveillance and device-control platform. Latest samples conditionally download a 23GB+ LLM module from Hugging Face, signaling experimentation with AI-assisted capabilities. Includes ransomware-style screen locker for device extortion.
How SURXRAT Android RAT works
SURXRAT is a next-generation Android Remote Access Trojan (RAT) that represents the convergence of mobile surveillance malware, AI experimentation, and commercial malware-as-a-service (MaaS) distribution. Uncovered by Cyble Research and Intelligence Labs (CRIL) in February 2026, SURXRAT has evolved from ArsinkRAT code into a feature-rich platform with novel capabilities.
The malware is marketed through a dedicated Telegram channel under the 'SURXRAT V5' branding, created in late 2024 with active development since early 2025. Over 180 related samples have been identified. The MaaS model offers two tiers: Reseller Plan (200K one-time, 3 builds/day, reselling rights) and Partner Plan (500K one-time, 10 builds/day, own reseller networks). As of January 2026, the platform reports 1,318 registered operator accounts.
SURXRAT evolved from ArsinkRAT, a cloud-native Android RAT previously tracked by Zimperium. ArsinkRAT used Firebase Realtime Database, Firebase Storage, Google Apps Script (uploading to Google Drive), and Telegram Bot API for C2/exfiltration. The predecessor campaign was massive: 1,216 unique APK hashes, 317 Firebase RTDB endpoints, and approximately 45,000 victim IPs across 143 countries. Largest victim concentrations in Egypt (~13K), Indonesia (~7K), Iraq (~3K), Yemen (~3K), and Türkiye (~2K). Distributed via Telegram, Discord, MediaFire links, impersonating 50+ brands (Google, YouTube, WhatsApp, Instagram, TikTok).
SURXRAT's key innovation is the conditional download of a large LLM module (>23GB) from Hugging Face. This download triggers when specific gaming applications are active (Free Fire MAX, Free Fire x JUJUTSU KAISEN) or when the C2 server sends target package names dynamically. The LLM module serves multiple purposes: deliberately introducing network latency during gameplay (paid cheating/disruption services), masking malicious background activity by degrading device performance, and enabling future AI-driven capabilities (automated interactions, adaptive social engineering).
The malware's C2 infrastructure uses Firebase Realtime Database (hxxps://xrat-sisuriya-default-rtdb.firebaseio[.]com) with the database reference labeled 'arsinkRAT', confirming the code lineage. Device registration uses random UUID for victim tracking.
SURXRAT provides comprehensive surveillance: SMS monitoring, contact/call log collection, Gmail account data, location tracking, notification interception, clipboard monitoring, browser history, cellular tower intelligence, WiFi scanning, file manager access. Remote control includes: device unlock, phone call initiation, wallpaper modification, audio playback, push notifications, forced URL opening, flashlight/vibration control, on-screen text overlays, and storage wipe.
The ransomware-style screen locker enables device locking with attacker-defined PIN and customizable lock message. Wrong PIN attempts are logged and transmitted to the operator in real-time. The lock can be remotely removed, giving complete control over device availability. This enables hybrid monetization: surveillance, fraud, or direct extortion based on victim value.
The Indonesian threat actor operates the platform, targeting aspiring cybercriminals rather than conducting attacks directly. The structured pricing, operational announcements, and feature updates demonstrate mature commercialization similar to underground SaaS platforms.
MITRE ATT&CK techniques used in TL-2026-0142
Credential Access
T1414 Clipboard Data; T1517 Access Notifications
Discovery
T1420 File and Directory Discovery; T1422 System Network Configuration Discovery; T1426 System Information Discovery; T1430 Location Tracking
Collection
T1429 Audio Capture; T1513 Screen Capture; T1533 Data from Local System; T1636.002 Protected User Data: Call Log; T1636.003 Protected User Data: Contact List; T1636.004 Protected User Data: SMS Messages
Command and Control
T1437.001 Application Layer Protocol: Web Protocols; T1481.002 Web Service: Bidirectional Communication
Impact
T1471 Data Encrypted for Impact; T1643 Generate Traffic from Victim
Initial Access
T1476 Deliver Malicious App via Other Means; T1660 Phishing
Defense Evasion
T1516 Input Injection; T1628.001 Hide Artifacts: Suppress Application Icon
Persistence
T1541 Foreground Persistence; T1624.001 Event Triggered Execution: Broadcast Receivers
Execution
defense-evasion
Exfiltration
T1639 Exfiltration Over Alternative Protocol; T1646 Exfiltration Over C2 Channel
Affected products and versions in SURXRAT Android RAT
- Google — Android
Vulnerable versions: All versions supporting accessibility services
Remediation for SURXRAT Android RAT
Immediate actions
- Block Firebase RTDB endpoint: xrat-sisuriya-default-rtdb.firebaseio.com
- Hunt for SURXRAT/ArsinkRAT APK hashes on managed Android devices
- Monitor for Hugging Face large model downloads (>23GB) from mobile devices
- Block known distribution channels on Telegram for SURXRAT V5
- Audit Android devices for suspicious accessibility service permissions
Workarounds
- Restrict sideloading on enterprise Android devices via MDM policy
- Block accessibility service grants for non-approved applications
- Monitor for unusual large downloads (>1GB) on mobile devices
Longer-term hardening
- Deploy mobile threat defense (MTD) with behavioral detection for Android RATs
- Implement app vetting for sideloaded APKs on enterprise Android devices
- Monitor Firebase RTDB traffic patterns for C2 communication indicators
- Enable Google Play Protect on all managed Android devices
- Educate users about risks of sideloading APKs from Telegram/Discord/MediaFire
Weaknesses (CWE) in SURXRAT Android RAT
CWE-200, CWE-306, CWE-940
Timeline of SURXRAT Android RAT
- SURXRAT operator creates Telegram channel for MaaS distribution. Suggests active malware development began shortly after.
- SURXRAT active development begins, building on ArsinkRAT codebase. Indonesian TA establishes MaaS platform with reseller/partner licensing.
- Zimperium reports increase in ArsinkRAT activity targeting Android devices. 1,216 unique APK hashes, 317 Firebase endpoints, 45,000 victim IPs across 143 countries.
- Zimperium coordinates with Google to take down malicious Firebase RTDB endpoints and Google Apps Script accounts used by ArsinkRAT. Google confirms known variants not on Google Play.
- Zimperium publishes comprehensive ArsinkRAT analysis documenting 4 operational variants, cloud-native C2 infrastructure, and global victim distribution. Source: https://zimperium.com/blog/the-rise-of-arsink-rat
- SURXRAT V5 branding appears. Operator publishes stats: 1,318 registered accounts, bot status active. Structured reseller (200K) and partner (500K) pricing established.
- Cyble identifies SURXRAT samples conditionally downloading 23GB+ LLM module from Hugging Face. Download triggered by gaming app detection (Free Fire) or remote C2 commands.
- Cyble publishes detailed SURXRAT analysis documenting AI-augmented capabilities, MaaS ecosystem, ransomware-style screen locker, and Firebase C2 infrastructure. Source: https://cyble.com/blog/surxrat-downloads-large-llm-module-from-hugging-face/
- As of 2026-05-29, SURXRAT remains an actively developed Telegram MaaS Android RAT with no CVE, no arrest, and no takedown reported (Cyble Feb 2026, Gurucul Mar 2026); operator stats show "Bot Status: Active" with 1,318 accounts and live Firebase C2. It survived ArsinkRAT's partial June-2025 takedown by rebuilding, and ongoing Hugging Face LLM experimentation confirms active capability expansion.
Sources cited for SURXRAT Android RAT
- Cyble: SURXRAT — From ArsinkRAT Roots to LLM Module Downloads Signaling Capability Expansion
- Zimperium: The Rise of ArsinkRAT — Cloud-Native Android RAT
- Zimperium ArsinkRAT IOC Repository
- MITRE ATT&CK Mobile: Application Layer Protocol
- Hugging Face Model Repository (LLM module source)
- Google Play Protect — Automatic Malware Protection
Threats related to SURXRAT Android RAT
Detection coverage for TL-2026-0142
As of 2026-02-24, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0142 across Splunk SPL, Microsoft KQL and Sigma, covering 16 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.