Android users—especially in Czech Republic and Slovakia—face a rapidly evolving cybersecurity threat. On September 9, 2025, researchers from ThreatFabric uncovered a potent new Trojan dubbed “RatOn.” This malware merges traditional banking trojan techniques with Near Field Communication (NFC) relay attacks, Automated Transfer System (ATS) fraud, and cryptocurrency wallet infiltration. The result is a multi-faceted, stealthy threat that operates with alarming automation and efficiency.
How RatOn Works
NFC Relay + Overlay Fraud
RatOn traces its origins to July 5, 2025, with ongoing development evident as late as August 29, 2025, confirming operators are continually refining its capabilities. It begins with a deceptive dropper app disguised on fake Play Store pages—sometimes under an adult-oriented name like “TikTok 18+”—targeting Czech and Slovak speakers. Once installed, the dropper requests installation from unknown sources and then escalates privileges, acquiring Accessibility Service and Device Administrator rights to gain deep system control. A third-stage payload, known as NFSkate, is then deployed—this component enables the Trojan to execute NFC relay (or “Ghost Tap”) attacks to skim data from physical cards.
Automated Transfers (ATS) and Crypto Wallet Takeover
Distinguishing RatOn from typical mobile trojans is its ATS capability. Once inside the system, RatOn can automatically open and navigate targeted banking apps—such as the Czech “George Česko”—simulating clicks and even typing the PIN to transfer funds without user input. It’s clear that operators have intimate knowledge of these banking interfaces. Moreover, RatOn actively seeks out cryptocurrency wallet apps—MetaMask, Trust Wallet, Blockchain.com, Phantom—auto-unlocks them, exposes seed phrases, logs keystrokes, and exfiltrates credentials to completely compromise the wallet.
Overlay Tricks and Ransom Threats
RatOn also delivers ransomware-style overlays and device locks, presenting fake ransom notes claiming users’ devices are locked for distributing illicit content. The message demands about USD 200 in cryptocurrency within a tight two-hour window—intended to panic users and push them into entering PINs or opening wallet apps, further enabling credential capture.
Expert Insight
Though the reporting does not include a direct expert quote, the analysis from ThreatFabric underscores the trojan’s uniqueness:
“Instances where a trojan evolves from a basic NFC relay tool into a sophisticated RAT with Automated Transfer System (ATS) capabilities are virtually unheard of. That’s why the discovery of the new trojan RatOn… is particularly noteworthy.”
This sentiment highlights how rare it is to see such a fully-blended mobile threat—spanning fraud, ransomware, overlay trickery, and crypto theft.
Conclusion
RatOn represents a worrying milestone in mobile threat evolution. Its multi-stage attack chain—deceptive dropper, escalated privileges, NFC relay, ATS fraud, crypto wallet compromise, and extortion—illustrates how far malware authors can go to maximize automation and minimize detection. As long as devices remain rooted in insecure sideloading and permissive accessibility frameworks, such threats will proliferate.
Mitigation advice:
- Avoid installing apps from unknown or unofficial sources—especially those promising adult-oriented or novelty content.
- Restrict sideloading and closely monitor apps with Accessibility or Device Admin privileges.
- Use reputable mobile security solutions and monitor NFC activity.
- Bank-institution defenders should implement behavioral anomaly detection to flag automated or unexpected transfers.
RatOn should serve as a wake-up call to both users and financial institutions: mobile devices, once considered secondary ransomware and fraud targets, are now front-line battlegrounds.
Please subscribe to the Newsletter so that you do not miss any critical update
