SURXRAT Trojan Operates as Malware-as-a-Service on Telegram

SURXRAT Trojan Operates as Malware-as-a-Service on Telegram

First seen 25 Feb 2026, 07:09 UTC CybleThecyberexpressGbhackersCybersecuritynewsCyberpress+3 53.6

Article Content

Browse articles
ThreatCluster

SURXRAT, an Android Remote Access Trojan (RAT), is being commercially distributed through a Telegram-based malware-as-a-service (MaaS) network. The operation allows affiliates to create customized builds while the core operator maintains centralized control. Cyble Research and Intelligence Labs (CRIL) have identified over 180 variants of SURXRAT.

Timeline

2026-02-24
Cyble reports on SURXRAT's development and distribution
2026-02-25
Thecyberexpress publishes details on SURXRAT's MaaS operation