Cellik Android RAT Exploits Google Play Store to Spread Malware + Video

Listen to this Post

Featured Image
The rise of sophisticated mobile threats is reaching new heights with the emergence of the Cellik Remote Access Trojan (RAT), a malware-as-a-service tool targeting Android devices. Unlike traditional malware, Cellik leverages the Google Play Store to create poisoned versions of legitimate apps, allowing attackers to discreetly compromise unsuspecting users. This development highlights the evolving landscape of mobile cybercrime, where even low-skilled attackers can now launch powerful spyware campaigns with minimal technical expertise.

How Cellik RAT Operates

Cellik is a RAT-as-a-service, meaning attackers can purchase access and control over compromised devices without deep technical knowledge. Once installed, the malware grants “complete control” over a victim’s Android device. iVerify’s research, led by Daniel Kelley, reveals that Cellik can stream the screen to attackers, operate the device remotely, and access critical data, including keylogs, notifications, one-time passcodes, browser credentials, and cloud storage directories.

Beyond typical RAT capabilities, Cellik introduces particularly dangerous features: app injection and Play Store integration. The injector allows attackers to overlay fake login screens on legitimate apps to steal credentials. Meanwhile, its Play Store component can automatically download legitimate apps, wrap them in a Cellik payload, and generate a malicious APK ready for distribution. This process aims to bypass Google Play Protect by masking malware inside trusted apps.

The RAT operates quietly, often relying on social engineering rather than exploiting device vulnerabilities. Users are tricked into installing compromised apps via sideloading, making vigilance in downloading practices essential. Cellik subscriptions range from $150 per month to $900 for a lifetime license, offering an affordable entry point for cybercriminals.

Key Features of Cellik

Full remote device control, including screen streaming and hidden navigation.

Keylogger and access to all notifications, one-time passcodes, and browser data.

File system browsing, download/upload capabilities, and encrypted exfiltration.

Malicious overlay injection on legitimate apps.

APK builder integrated with Google Play Store for bypassing security protections.

Silent background operation, relying on social engineering to spread.

Defending Against Cellik

Preventing infection requires vigilance and security hygiene. Users should prioritize official app stores, avoid sideloading apps unless necessary, and verify APKs manually. Security solutions with endpoint detection and response (EDR) capabilities can flag suspicious activity early, mitigating potential threats. Staying informed about social engineering tactics and maintaining updated device security is critical to preventing Cellik attacks.

What Undercode Say:

Cellik exemplifies the alarming professionalization of cybercrime targeting mobile platforms. RAT-as-a-service models like this reduce the technical barrier for attacks, transforming sophisticated malware into an accessible commodity. The integration of Play Store functionality is particularly concerning because it allows attackers to exploit user trust in official app marketplaces. By wrapping malware inside legitimate apps, Cellik sidesteps automated detection, demonstrating the limitations of current mobile security solutions.

From a strategic perspective, Cellik represents a shift in attacker behavior—from exploiting device vulnerabilities to exploiting human behavior. Social engineering becomes the primary attack vector, highlighting the continued importance of user education in cybersecurity defense. The RAT’s ability to exfiltrate data covertly, including cloud storage access, underscores the growing threat to personal and corporate information stored on mobile devices.

Cellik also illustrates a broader trend in the commercialization of malware. For a relatively low subscription cost, attackers can deploy sophisticated spyware with minimal effort, democratizing cybercrime. This creates a cascading effect where even inexperienced actors can conduct campaigns that were once the domain of skilled professionals. The result is a mobile ecosystem increasingly vulnerable to silent, persistent threats that evade detection until significant damage is done.

The automation of malicious app creation via Play Store integration suggests future RAT development will continue to exploit trusted platforms. Google’s Play Protect is a valuable defense, but it is not foolproof; attackers continually refine techniques to bypass automated reviews. Consequently, mobile security must evolve beyond reactive defenses, incorporating behavioral analysis, anomaly detection, and rigorous app verification processes.

Cellik’s presence also raises questions about accountability within app marketplaces. While users bear responsibility for safe downloading practices, the platform’s role in preventing malware distribution remains critical. The prevalence of malware-as-a-service models like Cellik may pressure platforms to strengthen vetting mechanisms, enforce stricter developer verification, and deploy AI-driven threat detection to catch obfuscated payloads before distribution.

Economically, Cellik highlights the low-cost, high-impact nature of modern mobile cybercrime. For attackers, subscription-based access provides flexible operational capacity without heavy upfront investment. For defenders, this means that even minor lapses in device hygiene can lead to major breaches. Organizations should therefore implement comprehensive mobile device management (MDM) policies, enforce app store restrictions, and educate users about phishing and sideloading risks.

Looking ahead, malware like Cellik may evolve to target emerging mobile technologies, including financial apps, digital wallets, and IoT integrations. Attackers are likely to leverage AI to automate payload customization, optimize social engineering tactics, and dynamically evade detection. Defenders must adopt a proactive security posture, combining technical controls, user awareness, and continuous threat intelligence to stay ahead of increasingly sophisticated mobile threats.

Fact Checker Results

✅ Cellik is a remote access Trojan targeting Android devices.
✅ It can wrap malicious payloads around legitimate Play Store apps.
❌ There is no evidence that Cellik relies on software exploits rather than social engineering.

Prediction

📊 As malware-as-a-service models like Cellik gain traction, mobile cybercrime will become increasingly automated and accessible. The Play Store and other official marketplaces may face stricter security scrutiny, while advanced behavioral monitoring tools will become essential for mobile threat mitigation. Users ignoring sideloading precautions will remain the primary vector for attacks, suggesting that social engineering-focused education will be a critical defense in the coming years.

▶️ Related Video (88% Match):

🕵️‍📝✔️Let’s dive deep and fact‑check.

References:

Reported By: www.darkreading.com
Extra Source Hub (Possible Sources for article):
https://www.quora.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2
Bing

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon