AndroRAT is an open-source Android remote access trojan implemented as a Java-based client/server application, with an Android client and a Java/Swing operator console. The client can run as a background service, start at device boot, and establish or activate communications following SMS or telephone-call triggers. It supports remote surveillance and device control, including collection of contacts, call logs, SMS messages, device and network details, location data, and Wi-Fi credentials; microphone and call recording; camera capture; screen capture; SMS monitoring, deletion, and sending; phone calls; file transfer; and shell-command execution. Some variants hide their application icon, abuse Android accessibility services for keylogging, and exploit CVE-2015-1805 to gain elevated privileges on vulnerable Android devices. AndroRAT has been used or customized in espionage activity associated with Bitter, ITG18, and Patchwork. Transparent Tribe adapted its codebase into the Android backdoor known as CapraRAT. Android devices are commonly targeted through trojanized applications and social-engineering lures distributed outside official app stores.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
This AndroRAT targets CVE-2015-1805, a publicly disclosed vulnerability in 2016 that allows attackers to penetrate a number of older Android devices to perform its privilege escalation. Google already patched CVE-2015-1805 in March 2016. | Trend Micro detected a new variant of Android Remote Access Tool (AndroRAT) (identified as ANDROIDOS_ANDRORAT.HRXC) that has the ability to inject root exploits to perform malicious tasks such as silent installation, shell command execution, WiFi password collection, and screen capture.
These attacks use dcRAT and QuasarRAT for Windows delivered via malicious documents exploiting CVE-2017-11882 — a memory corruption vulnerability in Microsoft Office... A typical infection would consist of a malicious document, such as an RTF file exploiting CVE-2017-11882, a stack overflow vulnerability that enables arbitrary code execution on a vulnerable version of Microsoft Office.
Bitter (aka APT-C-08 or T-APT-17) is suspected to be a South Asian hacking group motivated primarily by intelligence gathering, an operation that's facilitated by means of malware such as BitterRAT, ArtraDownloader, and AndroRAT.
Bitter (aka APT-C-08 or T-APT-17) is suspected to be a South Asian hacking group motivated primarily by intelligence gathering, an operation that's facilitated by means of malware such as BitterRAT, ArtraDownloader, and AndroRAT.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Bitter (aka APT-C-08 or T-APT-17) is suspected to be a South Asian hacking group motivated primarily by intelligence gathering, an operation that's facilitated by means of malware such as BitterRAT, ArtraDownloader, and AndroRAT.
Patchwork has also recently employed Android malware in its attacks, with its use of a customized version of AndroRAT.
In 2021, the group started to target the Android platform, using a modified version of an open-source RAT named AndroRAT. It bears similarities to CrimsonRAT, and has been named CapraRAT by Trend Micro in its research.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
This AndroRAT targets CVE-2015-1805... to perform its privilege escalation... The variant activates the embedded root exploit when executing privileged actions.
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
31 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android remote-access tool originally developed as an open-source university client/server project and later abused by cybercriminals. The described variant masquerades as TrashCleaner, exploits CVE-2015-1805 for root privileges, operates in the background, receives commands from a remote server, and steals device, communications, location, browser, Wi-Fi, and credential-related data. It can also record audio and calls, capture photos and screenshots, upload files, execute shell commands, forge or delete SMS, and silently enable accessibility services for keylogging.
Named as one of several Android malware/RAT tools the poster says they tested while seeking a working banking trojan with a control panel.
Commercial Android surveillanceware / RAT referenced as an earlier tool adopted by the actors before they developed customized tooling.
Commodity Android remote access trojan referenced as used in campaigns by Iranian APT groups.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.