Cyble
Read post

Glitch SPY RAT Distributed Via Fake Polish Rental App

Cyble Research and Intelligence Labs has identified a new Android malware family called Glitch SPY, distributed via a fake Polish apartment rental website that tricks users into sideloading an APK. The dropper is the known Brokewell Android Loader, which installs the Glitch SPY payload. Once installed, the RAT abuses Android Accessibility Service to auto-grant permissions and supports over 70 C&C commands covering live screen streaming, keylogging, SMS/contact/call log theft, camera and microphone surveillance, file management, shell execution, and remote browser control. A crypto-clipper module silently replaces copied cryptocurrency wallet addresses (ETH, TRON, Bitcoin) with attacker-controlled ones. A hidden remote browser runs on the victim's device using their IP and cookies, enabling stealthy web-based account takeover. The Builder module allows operators to generate customized payloads with configurable names, icons, and decoy URLs, indicating a reusable multi-campaign platform still under active development.

    #android#malware
Jun 30•18m read time•From cyble.com
Post cover image
Table of contents
Executive SummaryKey TakeawaysOverviewTechnical AnalysisConclusionOur RecommendationsMITRE ATT&CK® TechniquesIndicators of Compromise (IOCs)
428 Impressions
Cyble's image
Cyble

Cyble's publication is a resource for cybersecurity professionals and businesses seeking to stay ahe...

112 Followers

•

131 Upvotes

Would you recommend this post?

Copy link
WhatsApp
Facebook
X
New Squad
  • © 2026 Daily Dev Ltd.
  • Guidelines
  • Explore
  • Tags
  • Sources
  • Squads
  • Leaderboard