Skip to content
SURXRAT Trojan Operates as Malware-as-a-Service on Telegram

SURXRAT Trojan Operates as Malware-as-a-Service on Telegram

First seen 25 Feb 2026, 07:09 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 16:10 UTC

SURXRAT, an Android Remote Access Trojan (RAT), is being commercially distributed through a Telegram-based malware-as-a-service (MaaS) network. The operation allows affiliates to create customized builds while the core operator maintains centralized control. Cyble Research and Intelligence Labs (CRIL) have identified over 180 variants of SURXRAT.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 213d ago How this analysis works

Timeline

2026-02-24
Cyble reports on SURXRAT's development and distribution
2026-02-25
Thecyberexpress publishes details on SURXRAT's MaaS operation

More articles in this cluster (10)

Following this threat?

Track Surxrat in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed