Organizations should treat Android devices as untrusted when sideloading is allowed, and security awareness must stress: Never grant Accessibility permissions to apps you don’t 100% trust. Disclaimer: This write-up is for educational and defensive security purposes only. Analysis based on open-source intelligence and reverse engineering reports.

1. Overview Craxs RAT (often marketed as "Craxs Rat" or "Craxs Client") is a sophisticated Android Remote Access Trojan. Unlike commodity RATs, Craxs is sold as a RAT-as-a-Service (RaaS) on darknet forums and Telegram. Its primary differentiator is aggressive anti-uninstall and anti-analysis features, leading some analysts to call it "almost unkillable" on compromised devices.

Craxs Rat Here

  • Management Systems

    Payment Card Industry Data Security Standard

  • Certificate Holder

    PT Asuransi Jiwa IFG

  • Test Mark Number

    0000085107

The certificate holder's Management System corresponds to standard Payment Card Industry Data Security Standard.

Certificate scope

  • Payment Card Industry Data Security Standard

    E Commerce – Provisioning Credit Card Transaction Craxs Rat

Certificate for this Management System

Contact to the certificate holder

PT Asuransi Jiwa IFG

Graha CIMB Lt. 21
Jl. Jend Sudirman Kav. 58
Jakarta 12190
Indonesia