RadzaRat is an Android malware-as-a-service tool associated with mobile surveillance and remote device control. It has been advertised as an Android threat that masquerades as a legitimate file-management application and, once installed, provides operators with extensive access to the compromised device. Reported capabilities include remote file-system access, keystroke logging, persistence across device reboots, and command-and-control via Telegram. RadzaRat is part of a broader trend of increasingly capable Android MaaS offerings that lower the barrier to entry for mobile-focused cybercrime. Available information supports financially motivated criminal use, but high-confidence attribution to a specific country, operator cluster, or state sponsor is not currently available.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.