{"id":8389,"date":"2025-11-12T10:00:36","date_gmt":"2025-11-12T10:00:36","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/11\/12\/new-komex-android-rat-advertised-on-hacker-forums-with-multiple-subscription-options\/"},"modified":"2025-11-12T10:00:36","modified_gmt":"2025-11-12T10:00:36","slug":"new-komex-android-rat-advertised-on-hacker-forums-with-multiple-subscription-options","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/11\/12\/new-komex-android-rat-advertised-on-hacker-forums-with-multiple-subscription-options\/","title":{"rendered":"New KomeX Android RAT Advertised on Hacker Forums with Multiple Subscription Options"},"content":{"rendered":"<p>    New KomeX Android RAT Advertised on Hacker Forums with Multiple Subscription Options<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A newly identified Android remote access trojan (RAT) dubbed KomeX has surfaced on underground hacker forums, generating widespread concern within the cybersecurity community.<\/p>\n<p>Marketed by a threat actor under the alias \u201cGendirector,\u201d KomeX is built atop the infamous BTMOB RAT codebase and presents a formidable arsenal of spying and device control features.<\/p>\n<p>Recognized for its sophistication, KomeX is designed to compromise Android devices en masse, making it an enticing tool for cybercriminals seeking to monetize mobile infections.<\/p>\n<p>The malware\u2019s distribution tactics rely heavily on malicious Android apps pushed via unofficial marketplace sources and <a href=\"https:\/\/cybersecuritynews.com\/evolving-phishing-campaigns\/\" target=\"_blank\" rel=\"noreferrer noopener\">phishing campaigns<\/a>.<\/p>\n<p>Victims are typically enticed to install tampered applications or unwittingly click on convincing social engineering lures.<\/p>\n<p>What sets KomeX apart is its aggressive approach to obtaining device permissions almost immediately after installation, drastically expanding its reach and resilience once embedded in a target system.<\/p>\n<p>KrakenLabs security analysts were instrumental in <a href=\"https:\/\/x.com\/KrakenLabs_Team\/status\/1988162776473170216\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identifying<\/a> and dissecting KomeX after its forum debut.<\/p>\n<p>Their analysis revealed the trojan\u2019s ability to bypass Google Play Protect, stripping Android devices of a fundamental protective barrier against malware.<\/p>\n<p>Among its notable capabilities are high-fidelity live screen streaming, stealth audio and video capture via camera and microphone, instant access to SMS interception and manipulation, live geolocation tracking, remote control of all major apps, and full filesystem access layered with a covert <a href=\"https:\/\/cybersecuritynews.com\/how-to-detect-a-keylogger-on-your-computer-find-remove-keylogger-from-pc\/\" target=\"_blank\" rel=\"noreferrer noopener\">keylogger<\/a>.<\/p>\n<figure class=\"wp-block-embed aligncenter is-type-rich is-provider-twitter wp-block-embed-twitter\">\n<div class=\"wp-block-embed__wrapper\">\n<div class=\"embed-twitter\">\n<blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/s.w.org\/images\/core\/emoji\/16.0.1\/72x72\/1f6a8.png?ssl=1\" alt=\"\ud83d\udea8\" class=\"wp-smiley\" style=\"height: 1em; max-height: 1em;\"> New Android RAT for sale: <a href=\"https:\/\/twitter.com\/hashtag\/KomeX?src=hash&amp;ref_src=twsrc%5Etfw\">#KomeX<\/a> RAT<\/p>\n<p>The threat actor <a href=\"https:\/\/twitter.com\/hashtag\/Gendirector?src=hash&amp;ref_src=twsrc%5Etfw\">#Gendirector<\/a> is selling \u201cKomeX RAT\u201d: an Android remote-access trojan based on BTMOB on an underground forum.<\/p>\n<p><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/s.w.org\/images\/core\/emoji\/16.0.1\/72x72\/1f6e0.png?ssl=1\" alt=\"\ud83d\udee0\" class=\"wp-smiley\" style=\"height: 1em; max-height: 1em;\"> Claimed features include:<br \/>\u2022 Auto-grant all permissions<br \/>\u2022 Bypass Google Play Protect<br \/>\u2022 Live screen stream\u2026 <a href=\"https:\/\/t.co\/yDHwRz9oX1\">pic.twitter.com\/yDHwRz9oX1<\/a><\/p>\n<p>\u2014 KrakenLabs (@KrakenLabs_Team) <a href=\"https:\/\/twitter.com\/KrakenLabs_Team\/status\/1988162776473170216?ref_src=twsrc%5Etfw\">November 11, 2025<\/a>\n<\/p><\/blockquote>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script>\n<\/div>\n<\/div>\n<\/figure>\n<p>The RAT is sold with tiered pricing: short-term access, lifetime updates, or full source code for criminal syndicates seeking custom modifications.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-infection-mechanism\"><strong>Infection Mechanism<\/strong><\/h2>\n<p>Technically, KomeX maximizes its control by automatically requesting and securing invasive permissions through its AndroidManifest.xml configuration:-<\/p>\n<pre class=\"wp-block-code\"><code>&lt;uses-permission android:name=\"android.permission.SYSTEM_ALERT_WINDOW\"\/&gt;\n&lt;uses-permission android:name=\"android.permission.READ_SMS\"\/&gt;\n&lt;uses-permission android:name=\"android.permission.RECEIVE_BOOT_COMPLETED\"\/&gt;<\/code><\/pre>\n<p>Upon installation, KomeX abuses accessibility features to silently grant these permissions, enabling deep integration and persistent access.<\/p>\n<p>To resist removal, KomeX employs a fake uninstall module \u2014 simulating app deletion but secretly continuing operations in the background.<\/p>\n<p>Its infection lifecycle includes initial delivery, privilege escalation, secret data exfiltration, and durable anti-removal tactics, showcasing a complete, professional <a href=\"https:\/\/cybersecuritynews.com\/chatgpt-powered-malware-analysis\/\" target=\"_blank\" rel=\"noreferrer noopener\">malware<\/a> engineering approach.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/new-komex-android-rat-advertised-on-hacker-forums\/\">New KomeX Android RAT Advertised on Hacker Forums with Multiple Subscription Options<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/new-komex-android-rat-advertised-on-hacker-forums\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>New KomeX Android RAT Advertised on Hacker Forums with Multiple Subscription Options A newly identified Android remote access trojan (RAT) dubbed KomeX has surfaced on underground hacker forums, generating widespread concern within the cybersecurity community. Marketed by a threat actor under the alias \u201cGendirector,\u201d KomeX is built atop the infamous BTMOB RAT codebase and presents [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-8389","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/8389"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=8389"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/8389\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=8389"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=8389"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=8389"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}