AhMyth is an open-source Android remote access trojan used for surveillance and remote control of infected devices. Publicly available since the late 2010s, it has been widely reused, modified, and embedded into trojanized Android applications by both criminal operators and espionage actors. AhMyth has appeared in malicious apps distributed through official and third-party Android app stores, dedicated lure sites, social-media promotion, and repackaged applications that preserve benign functionality while covertly adding spyware features.
AhMyth is associated with Android-focused spying activity and supports collection of device data and user content. Reported capabilities across AhMyth and AhMyth-derived samples include theft of contacts and files, sending SMS messages, keylogging, screenshot capture, and interception of one-time passwords used for multi-factor authentication. Modified variants have added broader surveillance and post-compromise functionality such as continuous audio recording, deletion of selected SMS messages, downloading additional Android packages, and automated exfiltration of media, documents, messages, and application data.
The malware has been linked to multiple operational contexts. AhMyth-derived spyware has been observed in trojanized consumer-facing apps, including a music-streaming application that combined legitimate functionality with covert data theft and credential harvesting behavior. Customized AhMyth variants have also been used by Transparent Tribe against targets in India, including military and government personnel, delivered through themed Android lures and fake utility or entertainment apps. AhMyth’s code lineage has also influenced later Android malware projects, including frameworks inspired by or built from it.
AhMyth primarily targets Android devices and is best characterized as a commodity open-source RAT whose accessibility has enabled broad adoption, derivative development, and repeated use in espionage and surveillance campaigns.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The final malware is a modified version of the AhMyth Android RAT, open-source malware downloadable from GitHub, which is built by binding the malicious payload inside other legitimate applications.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
For C&C communication, Radio Balouch relies on its (now defunct) radiobalouch[.]com domain. This is where it would send information it has gathered about its victims... As with the account credentials, the C&C traffic is transmitted unencrypted over an HTTP connection.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as one of several Android malware/RAT tools the poster says they tested while seeking a working banking trojan with a control panel.
Open-source/commodity Android RAT referenced as used in campaigns by Iranian APT groups.
Mobile RAT family listed among top mobile threats; described at a high level as offering remote access and other advanced capabilities (not broken out per-family).
An Android RAT referenced in the report as sharing C2-linked infrastructure with Transparent Tribe activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.