RatMilad is an Android spyware family targeting mobile users in the Middle East, including enterprise device users. It has been distributed through trojanized applications promoted on social media and Telegram, where the malware masquerades as tools offering services such as VPN access, phone-number spoofing, or social-media account verification. Observed loader applications sideload the spyware outside official app stores and rely on victims granting extensive permissions during installation.
Once installed, RatMilad functions as a remote surveillance and data-theft implant. It can receive and execute operator commands, collect detailed device profiling information, enumerate installed applications and their permissions, harvest account information, and gather subscriber and handset identifiers such as IMEI, MAC address, phone number, SIM state, and related device metadata. It is also capable of stealing contacts, SMS messages, call logs, clipboard contents, GPS location data, and files stored on the device, including through directory listing and file-management operations. Additional functionality includes uploading collected data to command-and-control infrastructure, recording audio from the device, and modifying application permissions, including setting new permissions.
RatMilad communicates with its command-and-control infrastructure over HTTP, including use of HTTP POST for data transmission. Its feature set supports espionage, eavesdropping, and potentially extortion through broad access to personal and corporate mobile data. Reporting has assessed that the operators likely leveraged source code associated with the Iranian AppMilad hacker group and combined it with fraudulent Android applications to infect victims.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
RatMilad, a newly discovered Android spyware, has been stealing data from mobile devices in the Middle East.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
... RatMilad ... (v1.0) ...
Mobile RAT referenced as collecting account data (account names/types) from compromised devices.
RatMilad (v1.0)
Other documented malware strains include AridSpy, BouldSpy, GuardZoo, RatMilad, and SpyNote.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.