Surxrat Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
6
occurrences
First Seen
February 24, 2026
Last Seen
February 25, 2026

Related Threat Clusters

  • SURXRAT Trojan Operates as Malware-as-a-Service on Telegram

    SURXRAT, an Android Remote Access Trojan (RAT), is being commercially distributed through a Telegram-based malware-as-a-service (MaaS) network. The operation allows affiliates to create customized builds while the core…

    10 articles · Updated February 25, 2026
  • Cortex XDR Live Terminal Vulnerability Enables C2 Exploitation

    Research has revealed that attackers can exploit the Cortex XDR Live Terminal feature from Palo Alto Networks to establish command-and-control (C2) communications. This feature operates within a trusted endpoint…

    3 articles · Updated February 25, 2026

Recent Intelligence Reports

  • SURXRAT Malware Gives Hackers Complete Access To Android Devices — Cyberpress · February 25, 2026
  • SURXRAT Android RAT Attacking Users Gain Complete Device — Cybersecuritynews · February 25, 2026
  • Hackers Exploit Cortex XDR Live Terminal for C2 Communications — Gbhackers · February 25, 2026
  • Android RAT SURXRAT Grants Hackers Full Device Control and Data Exfiltration — Gbhackers · February 25, 2026
  • SURXRAT, a Trojan’s LLM — Thecyberexpress · February 25, 2026
  • SURXRAT Downloads Large LLM Module from Hugging Face — Cyble · February 24, 2026

CVSS v3.1 Breakdown