The post New Android RAT ‘Fantasy Hub’ sold as Malware-as-a-Service across Russian Telegram channels appeared on BitcoinEthereumNews.com. Cybersecurity researchers have announced a new Android RAT called Fantasy Hub that is being distributed as a subscription service to criminals. It is on sale on Russian-speaking Telegram channels under a Malware-as-a-Service (MaaS) model.  According to reports, it turns any app into spyware, pretends to be a Play Store update, hijacks SMS to steal 2FA, and streams camera and microphone in real-time via WebRTC. The Malware-as-a-Service model allows it to lower the technical barriers for attackers with minimal expertise. The spyware gives hackers the ability to read 2FA messages, get into bank accounts, and watch devices in real time. Fantasy Hub teaches criminals how to create fake Google Play Store According to its seller, the malware allows device control and espionage. This gives threat actors access to SMS messages, contacts, call logs, images, and videos, as well as the ability to intercept, reply to, and delete incoming alerts. The malware exploits the default SMS privileges, similar to ClayRAT, to gain access to SMS messages, contacts, the camera, and files. By prompting the user to set it as the default SMS handling app, the malicious program can obtain multiple powerful permissions in one go, rather than having to request individual permissions at runtime. Fantasy Hub hacking method: Source: Hackers Hub Criminals who are customers of the e-crime solution receive instructions related to creating fake Google Play Store landing pages for distribution, as well as the steps to bypass restrictions. Prospective buyers can choose the icon, name, and page they wish to receive a slick-looking page. The bot handles paid subscriptions and builder access. It’s also designed so that threat actors can upload any APK file to the service and receive a trojanized version that contains the malware built in. The service is available per user for a weekly price of $200… The post New Android RAT ‘Fantasy Hub’ sold as Malware-as-a-Service across Russian Telegram channels appeared on BitcoinEthereumNews.com. Cybersecurity researchers have announced a new Android RAT called Fantasy Hub that is being distributed as a subscription service to criminals. It is on sale on Russian-speaking Telegram channels under a Malware-as-a-Service (MaaS) model.  According to reports, it turns any app into spyware, pretends to be a Play Store update, hijacks SMS to steal 2FA, and streams camera and microphone in real-time via WebRTC. The Malware-as-a-Service model allows it to lower the technical barriers for attackers with minimal expertise. The spyware gives hackers the ability to read 2FA messages, get into bank accounts, and watch devices in real time. Fantasy Hub teaches criminals how to create fake Google Play Store According to its seller, the malware allows device control and espionage. This gives threat actors access to SMS messages, contacts, call logs, images, and videos, as well as the ability to intercept, reply to, and delete incoming alerts. The malware exploits the default SMS privileges, similar to ClayRAT, to gain access to SMS messages, contacts, the camera, and files. By prompting the user to set it as the default SMS handling app, the malicious program can obtain multiple powerful permissions in one go, rather than having to request individual permissions at runtime. Fantasy Hub hacking method: Source: Hackers Hub Criminals who are customers of the e-crime solution receive instructions related to creating fake Google Play Store landing pages for distribution, as well as the steps to bypass restrictions. Prospective buyers can choose the icon, name, and page they wish to receive a slick-looking page. The bot handles paid subscriptions and builder access. It’s also designed so that threat actors can upload any APK file to the service and receive a trojanized version that contains the malware built in. The service is available per user for a weekly price of $200…

New Android RAT ‘Fantasy Hub’ sold as Malware-as-a-Service across Russian Telegram channels

For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com

Cybersecurity researchers have announced a new Android RAT called Fantasy Hub that is being distributed as a subscription service to criminals. It is on sale on Russian-speaking Telegram channels under a Malware-as-a-Service (MaaS) model. 

According to reports, it turns any app into spyware, pretends to be a Play Store update, hijacks SMS to steal 2FA, and streams camera and microphone in real-time via WebRTC. The Malware-as-a-Service model allows it to lower the technical barriers for attackers with minimal expertise.

The spyware gives hackers the ability to read 2FA messages, get into bank accounts, and watch devices in real time.

Fantasy Hub teaches criminals how to create fake Google Play Store

According to its seller, the malware allows device control and espionage. This gives threat actors access to SMS messages, contacts, call logs, images, and videos, as well as the ability to intercept, reply to, and delete incoming alerts.

The malware exploits the default SMS privileges, similar to ClayRAT, to gain access to SMS messages, contacts, the camera, and files. By prompting the user to set it as the default SMS handling app, the malicious program can obtain multiple powerful permissions in one go, rather than having to request individual permissions at runtime.

Fantasy Hub hacking method: Source: Hackers Hub

Criminals who are customers of the e-crime solution receive instructions related to creating fake Google Play Store landing pages for distribution, as well as the steps to bypass restrictions. Prospective buyers can choose the icon, name, and page they wish to receive a slick-looking page.

The bot handles paid subscriptions and builder access. It’s also designed so that threat actors can upload any APK file to the service and receive a trojanized version that contains the malware built in. The service is available per user for a weekly price of $200 or a monthly price of $500. Users can also opt for a yearly subscription that costs $4,500.

The command-and-control (C2) panel associated with the malware provides details about the compromised devices, as well as information regarding the subscription status itself. The panel also provides attackers with the ability to issue commands to collect various types of data.

Fantasy Hub targets mobile banking users

The dropper apps have been found to act as a Google Play update, lending it a veneer of legitimacy and tricking users into granting the necessary permissions. It then uses fake overlays to obtain banking credentials associated with Russian financial institutions such as Alfa, PSB, T-Bank, and Sberbank.

Fantasy Hub integrates native droppers, WebRTC-based live streaming, and exploits the SMS handler role to steal data and impersonate legitimate apps in real-time.

According to Zimperium researcher Vishnu Pratapagiri, the spyware poses a direct threat to enterprise customers using BYOD. In addition, organization whose employees rely on mobile banking or sensitive mobile apps are in trouble.

 This comes after Zscaler ThreatLabz revealed that threat actors are using sophisticated banking trojans, such as Anatsa, ERMAC, and TrickMo. They often resemble genuine utilities or productivity apps in both official and third-party app stores. 

Once they’re installed, they employ very sneaky methods to obtain usernames, passwords, and even two-factor authentication (2FA) codes, which are required to complete transactions.

Additionally, CERT Polska has warned about new cases of Android malware called NGate, which attempts to steal card information from Polish bank users through Near Field Communication (NFC) relay attacks. 

When the victim opens the app in question, they are asked to prove their payment card by tapping it on the back of their Android device. The app then discreetly collects the card’s NFC data and sends it to a server controlled by the attacker or straight to a companion app installed by the threat actor who wants to get cash from an ATM.

Reports say that transactions using Android malware have gone up by 67% every year. They are powered by advanced spyware and banking trojans. About 239 malicious apps have been reported on the Google Play Store. Between June 2024 and May 2025, the apps were downloaded a total of 42 million times.

Join a premium crypto trading community free for 30 days – normally $100/mo.

Source: https://www.cryptopolitan.com/android-trojan-fantasy-hub-malware-on-sale/

Market Opportunity
PlaysOut Logo
PlaysOut Price(PLAY)
$0.03595
$0.03595$0.03595
+3.81%
USD
PlaysOut (PLAY) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Neom terminates $1bn tunnel contract at heart of The Line

Neom terminates $1bn tunnel contract at heart of The Line

Saudi Arabia’s Neom has cancelled a roughly $1 billion tunnelling contract at the heart of its flagship “The Line” giga-project, according to public documents.
Share
Agbi2026/03/18 11:28
Gold continues to hit new highs. How to invest in gold in the crypto market?

Gold continues to hit new highs. How to invest in gold in the crypto market?

As Bitcoin encounters a "value winter", real-world gold is recasting the iron curtain of value on the blockchain.
Share
PANews2025/04/14 17:12
These Are The XRP Price Targets You Need To Know Now: Cubic Analytics Founder

These Are The XRP Price Targets You Need To Know Now: Cubic Analytics Founder

Cubic Analytics founder Caleb Franzen says XRP is entering a decisive phase after months of compression, with the price structure implying a path toward the $6–$11 zone so long as the market defends what he calls the key risk line at $2.68. XRP Price Targets In a wide-ranging discussion on the Thinking Crypto podcast with host Tony Edward, Franzen stressed that his conclusions are grounded in “price, structure, and statistical signals” rather than narrative. “It’s the chart itself. It’s the structure itself,” he said. “So long as we stay above $2.68, we’re going much higher.” Franzen’s XRP view comes out of the same template he applies across digital assets: identify trend integrity, map the impulse-consolidation rhythm, and translate it into a ladder of Fibonacci extension targets on a logarithmic scale. In XRP’s case, he argues the market traced higher highs and then “tightened up” into a controlled series of lower highs—what he calls a classic volatility coil that “allows price to reset… for the next leg higher.” Related Reading: Social Media Turns Bearish On XRP: Is This A Buy Signal? He then anchors objective targets to that structure: using the most recent consolidation leg, he cites the 161.8% extension near roughly $4.40 and the 261.8% extension around $6. From the larger Q1 swing—Q1 highs to Q1 lows—he adds a second band of objectives at approximately $5.40 and $11.55. The message, in his words: “Those are the price targets that you have to be aware of if you’re holding and investing in XRP… so long as we stay above $2.68.” Risk management is central to how Franzen frames the trade. Rather than a maximalist forecast, he sets a clear invalidation level and treats it as a mechanical decision point. “If we fall below $2.68, you can get stopped out. You can reduce some of your exposure. You can slow down your DCA,” he said. “It’s okay to be wrong. It’s just not okay to stay wrong.” The Macro Angle Although the podcast also covered Bitcoin, Ethereum and Solana, Franzen’s macro and cross-asset framework is meant to contextualize, not overshadow, the XRP setup. He repeatedly described himself as “time agnostic,” declining to pin outcomes to a specific month or quarter and insisting that the tape, not the calendar, dictates probability. “I’ve been sharing [cycle] targets since the middle of 2023,” he noted, adding that the prudent path is to keep raising targets within an uptrend while letting invalidation handle the rest. That stance is informed by what he characterizes as resilient, supportive macro conditions—good enough for risk assets to trend without demanding a weak US dollar as a crutch. He pointed to strong real activity data and improving earnings assumptions as evidence that risk appetite is not being forced; it’s developing naturally. Related Reading: XRP Ready For $9 Blast — ‘Break $3.10 And It’s Game Over,’ Says Analyst Among the specific markers he flagged: Q2 real GDP growth at 3.8% with expectations of roughly 3.9% for Q3; prime-age unemployment near historic lows at about 3.8%; labor force participation rising; and both real and nominal wage growth, with wages around 4.1% year over year. In credit, he underscored tight spreads and high-yield corporates printing multi-year highs—“and if we adjust them for the dividend yield, they’re trading at all-time highs”—a combination that, in his experience, does not occur when markets are bracing for imminent stress. “As we’re looking at the weight of the evidence here, everything is coming together,” he said. “Higher highs and higher lows, increasing risk appetite, decent macro conditions, the Fed is cutting interest rates… We have to continue to have an upward bias.” That macro lens matters for XRP, he argues, because it reinforces the primacy of structure over story. He criticized a common assumption that crypto rallies must coincide with a falling dollar, highlighting that the US Dollar Index (DXY) has been roughly flat since mid-April while Bitcoin—and, by extension, broader crypto beta—advanced materially. He also described a composite lens that prices Bitcoin against a basket of global currencies (effectively offsetting BTC/USD by DXY) and said that index is making fresh all-time highs too, reflecting “weak global fiat currencies, not necessarily just a weak dollar.” The implication for XRP: if the broader liquidity and risk backdrop continues to reward trend persistence, then the technical coil and extension ladder have a cleaner runway. At press time, XRP traded at $2.8593. Featured image created with DALL.E, chart from TradingView.com
Share
NewsBTC2025/10/08 21:30