CRAX RAT (Remote Access Trojan) is one of the most notorious and widely circulated Android malware tools in black-hat circles, known for its extensive capabilities and stealth mechanisms. While it is often sold under different aliases, CRAX RAT is recognized for its modular structure, advanced evasion techniques, and seamless remote control capabilities. It is commonly used by underground actors, including individuals affiliated with Iranian, Indian, Turkish, and Russian-speaking hacker groups. In this document, we explore the tactical usage of CRAX RAT during offensive cyber operations, focusing on its attack lifecycle, delivery techniques, and operational usage.