AndroRAT is an open-source Android remote access trojan (RAT) used as a basis for multiple espionage-focused mobile implants. The content states that AndroRAT can send SMS messages, capture SMS messages, collect call logs, collect contact list information, and obtain device location via GPS or network settings. It is also referenced as part of the tooling used by several threat actors and campaigns.
The malware is directly associated in the content with South Asian espionage activity. Transparent Tribe (APT36) began targeting Android in 2021 using a modified version of the open-source AndroRAT; Trend Micro named that modified implant CapraRAT. Multiple reports cited in the content describe CapraRAT as loosely based on AndroRAT source code or as a second-stage implant based on open-source AndroRAT. Transparent Tribe used these Android implants in targeted campaigns against Indian and Pakistani users, including likely military or political targets, distributing trojanized apps outside Google Play via fake websites and social-engineering lures. Patchwork is also described as having used a customized version of AndroRAT in recent attacks. Volexity further reported that EvilBamboo’s BADSOLAR downloaded a second-stage JAR based on the open-source AndroRAT project. Cisco Talos lists AndroRAT among Bitter’s known tooling, and Lookout notes Iranian APT groups have leveraged tools such as Metasploit, AndroRat, and AhMyth in campaigns.
High-confidence capabilities explicitly mentioned in the content include SMS sending, SMS capture, call-log collection, contact theft, and location collection. The content does not provide standalone AndroRAT-specific indicators of compromise, but it repeatedly identifies AndroRAT as the open-source foundation for later Android spyware variants such as CapraRAT and BADSOLAR second-stage implants.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In 2021, the group started to target the Android platform, using a modified version of an open-source RAT named AndroRAT. It bears similarities to CrimsonRAT, and has been named CapraRAT by Trend Micro in its research.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Commodity Android remote access trojan referenced as used in campaigns by Iranian APT groups.
Android remote access trojan referenced as possible source-code inspiration for CapraRAT; documentation notes instability after Android version 9.
Open-source Android RAT referenced as the basis for the modified malware later named CapraRAT.
Android remote access trojan referenced as part of Bitter's cross-platform arsenal; specific capabilities are not detailed in the provided content.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.