RatMilad is an Android spyware and remote-access trojan associated with campaigns targeting enterprise mobile devices in the Middle East. It has been distributed through fake Android applications promoted on social media and Telegram, where victims were socially engineered into sideloading the app and granting extensive permissions. Known lures impersonated services related to VPN access and phone-number spoofing. Once installed, RatMilad provides broad surveillance and device-control capabilities. Reported functionality includes collection and exfiltration of contacts, SMS messages, call logs, files, clipboard contents, GPS location, installed-application data, and detailed device information. It can also record audio, capture photos, upload and delete files, enumerate directories, alter application permissions including accessibility-related permissions, and remain resident while awaiting further operator commands. These behaviors make it suitable for both personal surveillance and compromise of enterprise mobile data. The campaign appears to have been broad in scope rather than narrowly targeted at specific individuals. AppMilad has been cited as likely providing the code base used for RatMilad. The activity is best characterized as mobile spyware operations focused on data theft and persistent remote access rather than ransomware or disruptive attacks.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.