PlayPraetor is an Android remote access trojan (RAT) described as an evolving on-device malware threat. Reporting states it was launched in 2025 by Chinese-speaking developers/actors and is offered via a malware-as-a-service model, enabling global scaling of operations. It has been reported to infect more than 11,000 Android devices and has been observed targeting users across all major continents, with noted expansion in Spanish- and French-speaking regions. Documented capabilities include launching phishing attacks and stealing credentials from more than 200 applications. The available content associates PlayPraetor with Chinese-speaking operators but does not provide a more specific threat actor attribution. No high-confidence technical indicators of compromise are provided in the supplied content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android RAT/botnet spread via fake Google Play pages and Meta ads; infected 11,000+ devices with rapid growth (per summary).
Android remote access trojan (RAT) expanding in Spanish and French-speaking regions.
An Android RAT available as Malware-as-a-Service, capable of launching phishing attacks and stealing credentials from over 200 apps.
Android remote access trojan (RAT) attributed to Chinese-speaking actors, described as scaling globally (further details not provided in the excerpt).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.