Multiple threat actors, including cyber espionage groups, are employing an open-source Android remote administration tool called Rafel RAT to meet their operational objectives by masquerading it as Instagram, WhatsApp, and various e-commerce and antivirus apps.
“It provides malicious actors with a powerful toolkit for remote administration and control, enabling a range of malicious activities