New Android Malware ’Fantasy Hub’ Emerges as Malware-as-a-Service Threat
A new Android remote access trojan (RAT) dubbed 'Fantasy Hub' is being marketed as Malware-as-a-Service (MaaS) across Russian Telegram channels. The spyware masquerades as a Google Play Store update, hijacks SMS messages to bypass two-factor authentication (2FA), and enables real-time surveillance through device cameras and microphones via WebRTC.
The MaaS model significantly lowers the barrier to entry for cybercriminals, requiring minimal technical expertise. Fantasy Hub grants attackers comprehensive control over infected devices, including access to SMS messages, contacts, call logs, media files, and the ability to intercept or delete incoming notifications.
Notably, the malware exploits default SMS handling privileges to gain extensive permissions in a single step, mirroring techniques used by established threats like ClayRAT. The service includes tutorials for creating convincing fake Google Play Store landing pages, complete with customizable icons and branding to evade detection.