Thecyberexpress
SURXRAT Trojan Operates as Malware-as-a-Service on Telegram
First seen 25 Feb 2026, 07:09 UTC
•



+3
•53.6
Export
Article Content
Browse articles
SURXRAT, an Android Remote Access Trojan (RAT), is being commercially distributed through a Telegram-based malware-as-a-service (MaaS) network. The operation allows affiliates to create customized builds while the core operator maintains centralized control. Cyble Research and Intelligence Labs (CRIL) have identified over 180 variants of SURXRAT.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Timeline
2026-02-24
Cyble reports on SURXRAT's development and distribution
2026-02-25
Thecyberexpress publishes details on SURXRAT's MaaS operation
More articles in this cluster
Continue Reading
Google Addresses Eighth Chrome Zero-Day Vulnerability in 2025
Critical Exploitation of Cisco CM and Samsung KNOX Vulnerabilities
Google Fixes 107 Security Flaws in Android Update
Google Chrome Zero-Day Vulnerability CVE-2025-13223 Exploited in the Wild
Sandworm Launches Wiper Malware Campaign Against Ukrainian Organizations
Apple Alerts Users of Targeted Mercenary Spyware Attacks in 110 Countries