Close Menu
  • Home
  • Opinion
  • Region
    • Africa
    • Asia
    • Europe
    • Middle East
    • North America
    • Oceania
    • South America
  • AI & Machine Learning
  • Robotics & Automation
  • Space & Deep Tech
  • Web3 & Digital Economies
  • Climate & Sustainability Tech
  • Biotech & Future Health
  • Mobility & Smart Cities
  • Global Tech Pulse
  • Cybersecurity & Digital Rights
  • Future of Work & Education
  • Trend Radar & Startup Watch
  • Creator Economy & Culture
What's Hot

JB Monetary, Naver Cloud Check AI Use in Lending Below Threat-Management Framework

December 27, 2025

Prosperous Journey within the UAE Is Reshaping the Way forward for Luxurious Mobility

December 27, 2025

Know-how issues, however what issues extra is how we use it: MICA Director Jaya Deshmukh

December 27, 2025
Facebook X (Twitter) Instagram LinkedIn RSS
NextTech NewsNextTech News
Facebook X (Twitter) Instagram LinkedIn RSS
  • Home
  • Africa
  • Asia
  • Europe
  • Middle East
  • North America
  • Oceania
  • South America
  • Opinion
Trending
  • JB Monetary, Naver Cloud Check AI Use in Lending Below Threat-Management Framework
  • Prosperous Journey within the UAE Is Reshaping the Way forward for Luxurious Mobility
  • Know-how issues, however what issues extra is how we use it: MICA Director Jaya Deshmukh
  • CarDekho invests $10M in CollegeDekho
  • MassRobotics Launches the AMD Robotics Innovation Problem, Leveraging Adaptive Computing for Edge Robotics Functions
  • The 12 largest area tales of 2025 — in line with you
  • The Position of Attorneys in Guaranteeing Pedestrian Security: What You Must Know
  • World Community Tools-Constructing System (NEBS) Testing and Certification Providers Market is projected to achieve the worth of USD 4.99 billion by 2030.
Saturday, December 27
NextTech NewsNextTech News
Home - Cybersecurity & Digital Rights - ‘Cellik’ Android RAT Leverages Google Play Retailer
Cybersecurity & Digital Rights

‘Cellik’ Android RAT Leverages Google Play Retailer

NextTechBy NextTechDecember 18, 2025No Comments4 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email Copy Link
Follow Us
Google News Flipboard
‘Cellik’ Android RAT Leverages Google Play Retailer
Share
Facebook Twitter LinkedIn Pinterest Email


A distant entry Trojan (RAT)-as-a-service makes use of the Google Play Retailer to construct poisoned variations of Android apps. 

That RAT’s title is “Cellik,” and it was coated this week in analysis revealed by Daniel Kelley, analysis fellow with cellular safety vendor iVerify. Android malware is nothing new, however what makes this RAT stand out is that, along with your customary high-level performance, similar to full system management in opposition to a compromised goal, it is built-in with Google’s Play Retailer in as far as attackers can bundle it with in any other case reliable purposes. 

Cellik is one in all a rising class of “x-as-a-service” risk actor choices. Low-level cybercriminals can now pay for turnkey variations of every little thing together with ransomware, credential stealers, phishing kits, command-and-control (C2) infrastructure, and extra.

Kelley known as Cellik half of a bigger pattern of Android malware, a discipline that has matured to the purpose the place “even low-skilled attackers can now run cellular adware campaigns with minimal effort.”

How the Cellik RAT Works

As soon as the attacker manages to get Cellik onto a sufferer’s Android system, stated attacker is given “full management,” iVerify’s weblog defined. It may well stream the sufferer’s display screen on to the attacker, who can then remotely management the system as if holding it themselves. 

Associated:Why a 17-12 months-Previous Constructed an AI Mannequin to Expose Deepfake Maps

The Cellik operator additionally has entry to a keylogger, all on-screen notifications (together with alert historical past for any app), one-time passcodes, the total system’s file system, and delicate browser information (like cookies and auto-fill credentials). Mainly, something the person would have entry to, a profitable attacker would as nicely. 

“The controller can flick thru all recordsdata on the system, obtain or add recordsdata, delete information, and even entry cloud storage directories linked to the telephone. All file transfers and exfiltration are finished with encryption to keep away from detection,” Kelley wrote. Furthermore, “The attacker can remotely navigate to web sites, click on hyperlinks, and fill out types by way of this hidden browser, all with out the telephone’s proprietor seeing any exercise on their display screen.”

None of those options are too revolutionary in their very own proper, however Cellik turns into significantly harmful with its app injection and Play Retailer features. The previous characteristic permits the attacker to place malicious overlays over different apps on the compromised telephone, similar to pretend login screens that harvest credentials. It additionally contains an injector builder that may be custom-made for various purposes. 

On the Google Play entrance, the RAT-as-a-service contains an computerized .apk builder that may instantly browse the Google Play Retailer, obtain reliable apps, put a Cellik payload wrapper round them, and package deal it up for the attacker to distribute to different potential victims. 

Associated:Flaw in Hacktivist Ransomware Lets Victims Decrypt Personal Recordsdata

“The vendor claims Cellik can bypass Google Play safety features by wrapping its payload in trusted apps, basically disabling Play Shield detection,” Kelley wrote. “Whereas Google Play Shield sometimes flags unknown or malicious apps, Trojans hidden inside widespread app packages may slip previous automated evaluations or device-level scanners.”

Kelley tells Darkish Studying that these malicious apps are sometimes distributed in locations the place customers are prone to sideload them. “As soon as put in, it runs quietly within the background and connects to the attacker’s system. It doesn’t depend on exploits — simply social engineering and person belief.”

Takeaways, and Defending In opposition to Cellik

iVerify’s weblog explains that whereas different RATs provide some related capabilities to patrons, Cellik is notable for its Play Retailer options and the breadth of options for the associated fee, which ranges from $150 for a month to $900 for a lifetime subscription. 

For defenders, though cellular safety merchandise might catch malware like Cellik, the perfect recommendation could also be to remain updated on social engineering techniques and to look at what you obtain.

Associated:React2Shell Exploits Flood the Web as Assaults Proceed

“Stick with official app shops to attenuate publicity to malicious apps. Keep away from sideloading until completely obligatory, and should you should set up APKs manually, confirm hashes and signatures earlier than doing so,” Kelley says. “Having an [endpoint detection and response] resolution additionally helps so it could flag points as a person initiates a obtain and mitigates points early if a malicious app does make its manner by way of.”



Elevate your perspective with NextTech Information, the place innovation meets perception.
Uncover the newest breakthroughs, get unique updates, and join with a world community of future-focused thinkers.
Unlock tomorrow’s developments at present: learn extra, subscribe to our e-newsletter, and turn into a part of the NextTech neighborhood at NextTech-news.com

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
NextTech
  • Website

Related Posts

New MongoDB Flaw Lets Unauthenticated Attackers Learn Uninitialized Reminiscence

December 27, 2025

Belief Pockets Chrome Extension Breach Induced $7 Million Crypto Loss by way of Malicious Code

December 26, 2025

Santa Claus doesn’t exist (in accordance with AI) • Graham Cluley

December 26, 2025
Add A Comment
Leave A Reply Cancel Reply

Economy News

JB Monetary, Naver Cloud Check AI Use in Lending Below Threat-Management Framework

By NextTechDecember 27, 2025

Partnership focuses on credit score overview, transparency, and phased deployment quite than full automation Naver…

Prosperous Journey within the UAE Is Reshaping the Way forward for Luxurious Mobility

December 27, 2025

Know-how issues, however what issues extra is how we use it: MICA Director Jaya Deshmukh

December 27, 2025
Top Trending

JB Monetary, Naver Cloud Check AI Use in Lending Below Threat-Management Framework

By NextTechDecember 27, 2025

Partnership focuses on credit score overview, transparency, and phased deployment quite than…

Prosperous Journey within the UAE Is Reshaping the Way forward for Luxurious Mobility

By NextTechDecember 27, 2025

Taylor Journey Administration Group sees human-led, bespoke mobility turn into a core…

Know-how issues, however what issues extra is how we use it: MICA Director Jaya Deshmukh

By NextTechDecember 27, 2025

Ahmedabad (Gujarat) [India], December 27: MICA –The Faculty of Concepts on Sunday…

Subscribe to News

Get the latest sports news from NewsSite about world, sports and politics.

NEXTTECH-LOGO
Facebook X (Twitter) Instagram YouTube

AI & Machine Learning

Robotics & Automation

Space & Deep Tech

Web3 & Digital Economies

Climate & Sustainability Tech

Biotech & Future Health

Mobility & Smart Cities

Global Tech Pulse

Cybersecurity & Digital Rights

Future of Work & Education

Creator Economy & Culture

Trend Radar & Startup Watch

News By Region

Africa

Asia

Europe

Middle East

North America

Oceania

South America

2025 © NextTech-News. All Rights Reserved
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms Of Service
  • Advertise With Us
  • Write For Us
  • Submit Article & Press Release

Type above and press Enter to search. Press Esc to cancel.

Subscribe For Latest Updates

Sign up to best of Tech news, informed analysis and opinions on what matters to you.

Invalid email address
 We respect your inbox and never send spam. You can unsubscribe from our newsletter at any time.     
Thanks for subscribing!