An old Android RAT has returned with some new tricks - here is what to look out for

 An old Android RAT has returned with some new tricks - here is what to look out for

Published on March 28, 2025 | Category: tech

An old Android RAT has returned with some new tricks - here is what to look out for

News
By Sead Fadilpašić last updated

They say you can't teach an old dog new tricks, but an old RAT?

Android
(Image credit: Future)

  • Sophos researchers found a new variant of PJobRAT
  • Android RAT now targets Taiwanese users
  • The RAT can run shell commands and exfiltrate data

PJobRAT, an Android Remote Access Trojan (RAT) which disappeared roughly six years ago, has made a rather quiet comeback, targeting users with some arguably more dangerous functionalities.

Cybersecurity researchers from Sophos’ X-Ops security team discovered new samples in the wild, noting the 2019 PJobRAT could steal SMS messages, phone contacts, device and app information, documents, and media files, from infected Android devices.

The new variant can also run shell commands: “This vastly increases the capabilities of the malware, allowing the threat actor much greater control over the victims’ mobile devices,” Sophos explains. “It may allow them to steal data – including WhatsApp data – from any app on the device, root the device itself, use the victim’s device to target and penetrate other systems on the network, and even silently remove the malware once their objectives have been completed.”

Monitor your credit score with TransUnion starting at $29.95/month

Monitor your credit score with TransUnion starting at $29.95/month

TransUnion is a credit monitoring service that helps you stay on top of your financial health. With real-time alerts, credit score tracking, and identity theft protection, it ensures you never miss important changes. You'll benefit from a customizable online interface with clear insights into your credit profile. Businesses also benefit from TransUnion’s advanced risk assessment tools.

Preferred partner (What does this mean?)

View Deal

Inactive campaign

The 2019 variant was mostly targeting Indian military personnel, by spoofing different dating and instant messaging apps.

The new variant seems to have ditched the dating angle, and focuses exclusively on being an instant messaging app.

In fact, Sophos says that the apps actually work, and that the victims, if they knew each other’s IDs, could even communicate to one another.

Speaking of the victims, the attackers no longer target Indians, and have instead switched to the Taiwanese.

Are you a pro? Subscribe to our newsletter

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

By submitting your information you agree to the Terms & Conditions and Privacy Policy and are aged 16 or over.

Some of the apps found in the wild are called ‘SangaalLite’ (possibly a typosquatted version of ‘SignalLite’, an app used in the 2021 campaigns) and CChat (spoofing a legitimate app of the same name).

The apps were being distributed through WordPress sites, Sophos said, suggesting that they cannot be found on popular app stores. The sites have since been shut down, meaning that the campaign is probably completed, but the researchers reported them to WordPress anyway.

“This campaign was therefore running for at least 22 months, and perhaps for as long as two and a half years,” it was sad. However, it doesn’t seem to have been a large, or successful campaign, since the general public wasn’t the target.

Edit, April 8 - A Google spokesperson reached out to TechRadar Pro to confirm that there are no traces of this malware on the Google Play Store:

“Based on our current detection, no apps containing this malware are found on Google Play," they told us. "Android users are automatically protected against known versions of this malware by Google Play Protect, which is on by default on Android devices with Google Play Services. Google Play Protect can warn users or block apps known to exhibit malicious behavior, even when those apps come from sources outside of Play."

You might also like

  • Devious new Android malware uses a Microsoft tool to avoid being spotted
  • We've rounded up the best password managers
  • Take a look at our guide to the best authenticator app
TOPICS
Sead Fadilpašić

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

You must confirm your public display name before commenting

Please logout and then login again, you will then be prompted to enter your display name.

More about security
Ransomware

Port of Seattle ransomware breach exposes data on around 90,000 people

Laptop screen with red background and a warning sign in the middle

Still using WinRAR? It has a worrying security flaw that could let hackers hijack your Windows device

Latest
An image of the Panasonic Lumix ZS99 / TZ99

I ditched my smartphone for Panasonic’s new travel zoom compact – here’s what I learned

See more latest
Most Popular
Quiet PC UltraNUC Pro 14
This silent, fanless mini PC looks like a very refined and expensive Hi-Fi unit, and I'm surprised by how affordable it is
Google AI Mode Lens
Google’s AI Mode can explain what you’re seeing even if you can’t
Midjourney V7
Midjourney V7 gives the AI image-maker power, speed, and correctly shaped hands
Aoostar WTR Max Mini PC
This Ryzen-powered NAS is barely bigger than a shoe box and can hold 11 SSDs and HDDs, delivering more than 500TB of storage
Lexar PLAY PRO microSDXC Express card
This is the world's first 1TB microSD Express card to go on sale, just in time for the launch of the new Nintendo Switch 2
Manus sign up on a mobile phone.
Manus, the much-hyped Chinese AI, has opened up public access, and you get 1,000 credits for free if you sign up now
Ransomware
Port of Seattle ransomware breach exposes data on around 90,000 people
Big Brother logo – a multicoloured eye with a star for a pupil
How to watch Celebrity Big Brother 2025 online from anywhere – stream new series for free, channels, start times, housemates
A laptop showing OpenAI Sora and a dog sitting at a table surrounded by fire
ChatGPT subscribers are getting frustrated with Sora restrictions and OpenAI outages – and I can't blame them
Racks of servers inside a data center.
Does Microsoft know something we don't? Tech giant cools down on AI data center investment as another report claims company pullbacks

Related Articles

Spotify is about to be flooded with AI-made ads, and I wonder if it will make much of a difference to businesses

Spotify’s new AI-powered ad tool may not be the solution they claim....

Read More
CinemaCon 2025 live – first Avatar 3 reaction, juicy Fantastic Four news,

CinemaCon 2025 is officially underway – here are all new movie announc...

Read More
NYT Wordle today — answer and my hints for game #1385, Friday, April 4

Looking for Wordle hints? I can help. Plus get the answers to Wordle t...

Read More