Connect with us

Hi, what are you looking for?

Top Stories

SURXRAT Expands Capabilities by Downloading 23GB LLM Module from Hugging Face

SURXRAT expands its malware capabilities by incorporating a 23GB LLM module from Hugging Face, enhancing surveillance and exploitation tactics for cybercriminals.

A new variant of the Android Remote Access Trojan (RAT) known as SURXRAT has been identified, showcasing significant advancements over its predecessor, ArsinkRAT. According to research from Cyble, SURXRAT is currently being distributed through a Telegram-based malware-as-a-service (MaaS) model, enabling a more extensive reach for cybercriminals. This latest iteration, branded as SURXRAT V5, not only enhances traditional surveillance capabilities but also introduces the ability to download large language model (LLM) modules, indicating a sophisticated evolution in its operational functions.

Launched by an Indonesian threat actor, SURXRAT operates through a channel where it is marketed and regularly updated, allowing affiliates to create and distribute customized versions while still being controlled by a centralized infrastructure. Technical analysis reveals that SURXRAT functions as a comprehensive surveillance tool capable of extensive data exfiltration and real-time device control. Its ability to leverage accessibility permissions for persistent control further complicates detection efforts, as it connects to a Firebase-based command-and-control (C&C) infrastructure.

The malware reportedly collects sensitive information such as SMS messages, contacts, call logs, and GPS data, facilitating credential theft and financial fraud. The introduction of the LLM module suggests that the operators are experimenting with AI-assisted functionalities that may augment existing capabilities, potentially for device manipulation or alternative monetization strategies. The LLM module, which surpasses 23GB, is downloaded under specific conditions, such as when certain gaming applications are used, indicating a targeted approach to its deployment.

The evolution of SURXRAT signifies a growing trend in the Android malware landscape, reflecting the increasing professionalization and scalability of cybercrime. The structured pricing tiers and licensing models employed by the operators enable targeted distribution, allowing aspiring cybercriminals to exploit the evolving threat environment. This MaaS model, akin to legitimate software-as-a-service offerings, underscores a shift toward a more organized criminal ecosystem.

As the threat actor maintains and updates SURXRAT, the malware’s capabilities have expanded to include a ransomware-style screen locker feature, which can deny device access until a ransom is paid. This dual functionality—spying and extorting—highlights a hybrid monetization strategy, effectively allowing operators to switch tactics based on victim profiles. The malware’s success in this evolving ecosystem suggests that it not only seeks to gather information but also to exploit it for profit through intimidation.

In light of these developments, cybersecurity experts recommend several best practices for users to protect themselves against such threats. These include installing applications only from verified sources, being cautious with app permissions, enabling multi-factor authentication for sensitive accounts, and maintaining up-to-date mobile security solutions. Such measures can provide essential defenses against the increasingly sophisticated tactics employed by malware like SURXRAT.

As SURXRAT continues to adapt and evolve, the implications for individual users and organizations alike are significant. The combination of advanced surveillance capabilities, ransomware functionality, and the incorporation of AI highlights the necessity for improved threat detection and user awareness in an era where mobile devices are pivotal in daily life. The ongoing development of such malware serves as a reminder of the persistent risks in the digital landscape, reinforcing the need for vigilance among all users.

See also
Staff
Written By

The AiPressa Staff team brings you comprehensive coverage of the artificial intelligence industry, including breaking news, research developments, business trends, and policy updates. Our mission is to keep you informed about the rapidly evolving world of AI technology.

You May Also Like

Top Stories

Nvidia enters South Korea's AI market by launching 7 million Korean-language personas and the multimodal Nemotron3 Nano, aiming to establish market dominance.

Top Stories

Multiverse Computing unveils the LittleLamb AI model family on Hugging Face, reducing model size by 50% while enhancing performance for edge and mobile applications.

Top Stories

DeepSeek's V4-Pro eclipses GPT-5 and Claude in key benchmarks, achieving a Codeforces rating of 3,206 while undercutting OpenAI's costs by 89% per million tokens.

Top Stories

Hugging Face launches ML Intern, an open-source AI agent that surpasses Claude Code in scientific reasoning with a 32% GPQA score, offering $1,000 in...

Top Stories

Anonymous developer RizenML claims to have trained a 235M parameter language model on a single Nvidia RTX 5080 in 14 days, challenging traditional AI...

AI Cybersecurity

Authorities uncover 350 organized groups and 320 amateur hackers in a vast cyber threat network, as cyberattacks quadruple amid rising AI risks

Top Stories

Threat actors exploit the Marimo Python notebook vulnerability (CVE-2026-39987) to deploy NKAbuse malware via Hugging Face, launching 662 attacks in just three days.

Top Stories

Hugging Face's HoloTab Chrome extension enables AI models to mimic human behavior in web applications, enhancing automation without site-specific integrations.

© 2025 AIPressa · Part of Buzzora Media · All rights reserved. This website provides general news and educational content for informational purposes only. While we strive for accuracy, we do not guarantee the completeness or reliability of the information presented. The content should not be considered professional advice of any kind. Readers are encouraged to verify facts and consult appropriate experts when needed. We are not responsible for any loss or inconvenience resulting from the use of information on this site. Some images used on this website are generated with artificial intelligence and are illustrative in nature. They may not accurately represent the products, people, or events described in the articles.