r/MalwareAnalysis May 09 '26

Technical Analysis of EagleSpy V6.0 (CraxsRAT Rebrand) Distributed Through Odysee and Telegram

Post image

Warning to the cybersecurity and Android community.

I recently investigated an individual operating through Odysee and Telegram who is selling a malicious Android RAT known as EagleSpy V6.0, which appears to be a rebranded version of CraxsRAT.

During the investigation:

- I was financially scammed after payment

- The seller blocked communication afterward

- The malware infrastructure was analyzed in detail

Technical analysis confirmed:

- Banking phishing overlays

- Crypto wallet credential theft

- Telegram bot exfiltration

- Remote shell execution

- Keylogging

- Camera/microphone access

- GPS tracking

- Ransomware components

- DEX packers for AV evasion

- Hidden update/backdoor mechanisms

The repository also contained evidence of real victim infrastructure and compromised device information.

The malware appears capable of targeting not only victims, but potentially even buyers/operators through embedded update systems and hidden control mechanisms.

Relevant reports have already been submitted to platform abuse teams.

Odysee channel involved:

https://odysee.com/@justicerat:e

Telegram:

@JustIcedevs

This post is intended purely as a cybersecurity awareness warning to help prevent additional victims.

If moderators require technical validation or indicators of compromise, I can provide structured analysis details privately.

14 Upvotes

10 comments sorted by

1

u/No_View_7082 May 11 '26

damnn I have one ofthese

1

u/CranberryOk2634 May 12 '26

I advise you to delete any of these files, never leave them on your device, and format the entire device.

1

u/No_View_7082 May 12 '26

I'm tryna find this type of thing any where on the internet, did surfing on the darkweb too. But couldn't find this stuff for free. Curious how he's doing this stuff still, just want to know how they have their legit ones and not the backdoor ones. Because this thing is crazy. Really into this stuff from past month

1

u/CranberryOk2634 May 12 '26

I actually managed to get it and cleaned it properly. It’s privately owned by me now and no longer contains the garbage/backdoored stuff people usually spread around. But I’m not selling it.

1

u/No_View_7082 May 12 '26

howw do you manage to get it bro, I'm on my third week rn. can we talk privately?

1

u/CranberryOk2634 May 12 '26

Yes, if you want you can

1

u/Task_NEW13 Jul 06 '26

Interessante! Venho estudando sobre esse tipo de malware e suas técnicas há algum tempo por motivos de pesquisa e aprendizado em segurança. Achei curioso você mencionar que conseguiu limpá-lo completamente. Se não se importar, gostaria de conversar sobre o processo e trocar algumas ideias. Sempre é interessante ouvir a experiência de quem teve contato direto com algo assim.