Cellik Android RAT: Everything You Need to Know to Stay Protected

Published By: X10 Technologies
Date Published: July 28, 2026 

A new strain of Android malware called Cellik is a clear sign of where mobile threats are heading. It does the kind of surveillance that used to be reserved for expensive, government grade spyware, but it is sold as a monthly subscription that almost anyone can rent. What makes it especially worrying is how it spreads. Cybercriminals can wrap Cellik inside a copy of a real, popular app, so the malicious version looks and behaves like the app you actually wanted.

This article explains what Cellik is, what it can do to an infected phone, how it gets onto a device, the warning signs to watch for, and the practical steps you can take to protect yourself and your organization.

WHAT IS CELLIK?

Cellik is an Android Remote Access Trojan, usually shortened to RAT. A RAT is malware that gives an attacker remote control over a device. Once it is installed, the operator can watch, listen, read, and act on the phone from anywhere in the world, often without the owner noticing anything at all.

Cellik was first documented in December 2025 after security researchers found it being advertised on cybercrime channels. Since then it has been covered by a range of security news outlets, including SecurityWeek, Dark Reading, and BleepingComputer. So while it is relatively new, it is a real and independently verified threat, not a rumor.

Cellik Android RAT

Cellik is sold as Malware as a Service, or MaaS. This is the same subscription model you see with legitimate software. The people who build the malware rent it out through a control panel, handle the back end infrastructure, and provide tutorials and support, while their customers point it at victims. The result is that even people with little technical skill can run a surveillance campaign.

Reporting on the malware puts the entry price at roughly a few hundred dollars a month, which tells you how cheap and accessible this kind of capability has become. That low cost is the whole point of the business model, and it is why threats like this are spreading.

Cellik is not the first tool of its kind. Researchers have tracked similar Android MaaS families such as HyperRat, PhantomOS, and Nebula. What sets Cellik apart is the breadth of what it can do for the price, and one feature in particular that we will come back to below: its ability to hide inside legitimate Play Store apps.

WHAT CELLIK CAN DO TO AN INFECTED PHONE

Once Cellik is running on a device, it gives the attacker a wide and unpleasant range of control. The capabilities below are the ones confirmed in the published research. Think of them less as a technical spec sheet and more as a list of everything you stand to lose.

Cellik Android RATLive screen viewing and remote control. The attacker can stream your screen in real time with very little delay, essentially watching your phone as if they were looking over your shoulder. They can also take over the interface, simulating taps and swipes as though they were holding the device. In practice this works like an invisible remote desktop session running on your phone.

Keylogging. Cellik can record what you type across the device. Anything you enter, including passwords, private messages, and search queries, can be captured.

Notification interception. The malware can read all of your notifications, both the live ones as they arrive and the earlier history. This is more dangerous than it sounds, because one time passcodes and two factor authentication codes usually arrive as notifications or text messages. If an attacker can read those, then a second factor that is supposed to protect your accounts stops protecting you.

Camera and microphone access. The operator can access the front and back cameras and the microphone, which allows remote photos, audio recording, and live listening.

Full file access. Cellik can browse your entire file system, download files off the device, upload new files onto it, delete data, and reach cloud storage folders that are linked to the phone. All of this is done over encrypted connections, which makes the activity harder to spot on the network.

A hidden browser for session hijacking. This is one of Cellik’s more insidious features. It runs an invisible web browser in the background that you never see on your screen. The attacker can use it to open websites, click links, and fill in forms, all while receiving a live stream of screenshots. Because your phone is already logged into your accounts, the attacker can use your saved sessions and cookies to get into those accounts, or quietly submit credentials on phishing pages. If you are tricked into entering a password or card number, the malware captures it.

Overlay and injection attacks. Cellik can draw fake screens on top of your real apps. A common version of this is a counterfeit login screen that appears over your banking or email app. You think you are logging into your bank, but you are actually handing your credentials straight to the attacker. Cellik includes a builder for creating these fake overlays for specific apps, and it can run several of them at once. That means it can be phishing your banking login and your email login at the same time, feeding both back to the attacker.

Beyond these confirmed features, the people selling Cellik advertise an expanding feature set in newer versions, including things like location tracking, cryptocurrency wallet theft, and other data collection. It is worth being a little skeptical of every claim a criminal seller makes, since marketing copy is often inflated. But the core capabilities above have been documented by researchers, and on their own they are more than enough to drain a bank account, take over online accounts, and expose a person’s private life.

WHY CELLIK IS MORE DANGEROUS THAN TYPICAL ANDROID MALWARE

Most of Cellik’s individual features can be found in other Android RATs. The reason it has drawn so much attention is how it is distributed.

Cellik’s control panel is integrated with the Google Play Store. Through that panel, an attacker can browse the Play Store catalogue, pick a legitimate and popular app, and with a single click generate a new malicious version of it. The tool wraps the Cellik payload inside the real app and repackages it as an installer file. The end product looks like the app you wanted, because it is built around the app you wanted, but it secretly installs the malware in the background.

Cellik Android RAT

This matters for two reasons.

First, it removes the technical skill that used to be required to disguise malware. In the past, repackaging an app took some effort and know how. Cellik turns it into a one click operation, which is why researchers describe it as lowering the barrier to entry for mobile spying.

Second, it undermines a habit that many people rely on for safety. A lot of us assume that if an app looks and works like the real thing, it is the real thing. Cellik is specifically designed to break that assumption. The sellers even claim their wrapping technique can slip past Google Play Protect by hiding inside trusted app packages. It is important to be precise here: Google has not confirmed that Cellik actually defeats Play Protect, and Play Protect does block a great deal of malware. But the practical takeaway for you as a user is simple. You cannot judge whether an app is safe just because it looks familiar, especially if it did not come from the official store.

HOW CELLIK GETS ONTO A DEVICE

Cellik Android RATUnderstanding how a phone gets infected is the key to avoiding it, because almost every infection path requires the victim to take an action.

The main route is sideloading, which means installing an app from somewhere other than the official Google Play Store, usually as a standalone APK file. Cellik’s repackaged apps are spread through channels like these:

Links in phishing emails and scam text messages, sometimes called smishing, that push you to download an app or an update

Fake or unofficial app stores and download sites

Websites offering free, cracked, or modified versions of paid apps and games

Fake update prompts that claim your phone or an app needs an urgent update

Direct messages or files sent by an attacker who is socially engineering you into installing something

The common thread is that a person is persuaded to install an app that came from outside the official store. Cellik does not magically appear on a locked down phone on its own. Someone has to be convinced to open the door. That is good news, because it means careful habits go a long way.

There is also a more targeted scenario worth naming. Because installing Cellik requires access to the device or the ability to trick the owner, this class of malware is sometimes used by people who have physical or personal access to a victim, for example in cases of stalking or domestic abuse. If you have reason to believe someone with access to your phone may have installed monitoring software, treat that as a serious situation and consider seeking help from a professional or a support organization rather than confronting it alone.

WARNING SIGNS YOUR PHONE MAY BE INFECTED

Cellik is built to stay hidden, so there is no single obvious red flag. It can hide its icon, run quietly in the background, and keep itself out of your recent apps list. That said, malware that is constantly streaming your screen, logging keys, and phoning home tends to leave traces. Watch for a combination of the following:

Cellik Android RAT

Faster than normal battery drain, or the phone feeling warm when you are not using it

A noticeable jump in mobile data usage that you cannot account for

The phone feeling sluggish, freezing, or restarting on its own

The screen lighting up, flickering, or showing brief flashes when you are not touching it

Apps you do not remember installing, or an app that seems to have no real purpose

A login screen or permission prompt that looks slightly off, or an app that unexpectedly asks for very broad permissions

Unexpected two factor codes arriving, or notifications that you have logged into an account you did not log into

Google Play Protect or your security software flagging an app

One honest caveat: a well built RAT is designed specifically to avoid these symptoms, so the absence of warning signs is not proof that a device is clean. If you have a concrete reason to be worried, act on it rather than waiting for symptoms to appear.

HOW TO CHECK YOUR PHONE RIGHT NOW

You do not need to be a security expert to do a basic self check. The following steps go through the settings that malware like Cellik depends on. Exact menu names vary a little between phone brands and Android versions, but the ideas are the same.

Review which apps have Accessibility access. Accessibility permissions are one of the most powerful things an app can hold on Android, because they allow an app to read the screen and act on your behalf. Malware relies heavily on them. Go into Settings, find Accessibility, and look at the list of apps that have it turned on. If anything there is unfamiliar or does not have a legitimate reason to need it, that is a serious red flag.

 

Cellik Android RAT

 

Review Device Admin apps. In Settings, look for Device admin apps or Device administrators, often under Security. Malware sometimes registers here to make itself harder to remove. Turn off anything you do not recognize.

Review apps with special permissions. Check which apps can display over other apps, which can read your notifications, and which have usage access. On most phones these live under Settings, Apps, then Special app access. Overlay and notification permissions are exactly what an overlay and interception attack needs.

Look through your full app list. In Settings, Apps, view all installed apps rather than just the ones showing on your home screen. Hidden or oddly named apps that you did not install deserve suspicion.

Run a Play Protect scan. Open the Google Play Store, tap your profile icon, choose Play Protect, and run a scan. Make sure Play Protect is turned on while you are there.

Check battery and data usage by app. In battery and data settings you can usually see which apps are consuming the most. An unfamiliar app near the top of either list is worth investigating.

Confirm that installing unknown apps is turned off. Look for the setting that allows installing unknown or third party apps and make sure it is disabled for your browsers and messaging apps. This is the switch that sideloaded malware needs.

HOW TO PROTECT YOURSELF

Cellik Android RAT

Prevention is far easier than cleanup. These habits will keep you safe from Cellik and from the great majority of Android malware.

  • Install apps only from the official Google Play Store, and be cautious even there. Avoiding sideloaded APKs is the single most effective thing you can do, because sideloading is the main way this malware spreads.
  • Keep installing unknown apps disabled. Only enable it briefly if you have a genuine, specific reason, and turn it off again right away.
  • Be very suspicious of Accessibility requests. If a game, a wallpaper app, a flashlight, or any simple utility asks for Accessibility access, that is a major warning sign. Very few everyday apps have a legitimate need for it.
  • Scrutinize permissions before you tap accept. Ask whether the permission makes sense for what the app does. A photo editor does not need to read your text messages. A calculator does not need your call logs.
  • Avoid cracked, modded, or pirated apps. Free versions of paid apps are a classic delivery method for malware. The savings are not worth it.
  • Be skeptical of links in texts and emails, especially ones that create urgency or push you to download something. When in doubt, go to the official source directly rather than tapping the link.
  • Keep Android and your apps updated, and keep Play Protect on. Security updates close the holes that malware uses, and Play Protect blocks a large amount of known malware automatically.
  • Prefer stronger forms of authentication over SMS codes where you can. Because Cellik can read notifications and text messages, one time codes delivered by SMS are a weak second factor against it. App based authenticators, hardware security keys, and passkeys are all harder for this kind of malware to defeat.
  • Consider a reputable mobile security or mobile threat detection product, particularly if your phone holds sensitive personal or work data. On the business side, mobile endpoint detection can flag a suspicious app the moment a download begins.

WHAT TO DO IF YOU THINK YOU ARE INFECTED

If you have real reason to believe Cellik or similar malware is on your device, move carefully and in this general order.

  1. Assume the device is being watched. Do not use the possibly infected phone to change passwords or log into sensitive accounts, because the attacker may capture whatever you type.
  2. Disconnect it from the internet. Turning off Wi Fi and mobile data cuts the malware off from its operator and stops live surveillance and data theft.
  3. From a different, trusted device, secure your accounts. Change the passwords on your important accounts, especially email and banking, and sign out all active sessions where the option exists. Turn on two factor authentication using an app or a security key rather than SMS.
  4. Contact your bank if there is any financial exposure, so they can watch for fraud and lock things down if needed.
  5. Back up only the essentials, then factory reset the device. A factory reset is the most reliable way to remove this kind of malware. Reinstall your apps from the official store afterward, and do not restore a backup that might contain the malicious app.
  6. In a workplace context, report it to your IT or security team immediately. A compromised phone that touches company email or systems is an organizational problem, not just a personal one.

 

Cellik Android RAT

 

If you are a high risk individual, for example a journalist, an executive, or someone worried about a personal threat, consider engaging a professional for a proper forensic examination before you wipe the device, since a reset also destroys the evidence.

WHAT THIS MEANS FOR ORGANIZATIONS

Cellik Android RAT

Cellik represents a broader shift in cybercrime: mobile phones are now a serious part of the attack surface, and they are often the least protected part. Employees carry corporate email, chat, files, and account access in their pockets, frequently on personal devices under a bring your own device arrangement. A single compromised phone can expose credentials, intercept multi factor codes, and give an attacker a foothold into systems that are otherwise well defended.

Defending against this is about layers rather than any single product. It generally includes clear mobile usage and app policies, mobile device management or mobile threat detection so that risky apps and compromised devices can be spotted, app vetting for anything that touches corporate data, ongoing security awareness training so that staff recognize smishing and fake app lures, and a tested incident response plan for when a device is compromised.

KEY TAKEAWAYS

  • Cellik is a rentable Android RAT, first documented by iVerify in December 2025, that gives attackers deep control over an infected phone.
  • Its standout danger is that it can hide inside repackaged copies of legitimate Play Store apps, which makes malicious apps hard to tell apart from real ones.
  • It can steal passwords, read your two factor codes, hijack logged in sessions, and put fake login screens over your banking and email apps.
  • It almost always arrives through sideloading, so installing apps only from the official store, and refusing Accessibility requests from apps that have no reason to need them, are your strongest defenses.
  • If you suspect an infection, get the device offline, secure your accounts from a clean device, and factory reset the phone.

HOW X10 TECHNOLOGIES CAN HELP

At X10 Technologies, we help organizations across the region strengthen their security posture, including the mobile devices that are so often overlooked.

Whether you need help evaluating your mobile and endpoint defenses, delivering security awareness training so your team can recognize threats like Cellik, or responding to a suspected compromise, our team is here to help.

Reach out to us to start a conversation about protecting your people and your data.

SOURCES AND FURTHER READING