WolfRAT is an Android remote access trojan used for mobile surveillance and data theft. It has been observed masquerading as trusted or benign Android applications, including fake Google- and update-themed apps, to reduce user suspicion and facilitate installation. Once active on a device, it supports broad collection of victim data, including SMS messages, call logs, contact lists, installed application information, user account data, browser history, photos, and arbitrary files. It can also capture photos and videos using the device camera and exfiltrate device-identifying information such as the IMEI alongside stolen data.
WolfRAT also provides active device-manipulation capabilities. It can send and delete SMS messages, enabling both surveillance and impact-oriented abuse of the victim’s messaging environment. For discovery, it can enumerate installed applications and use Android system utilities to determine whether specific applications are running, which can help operators profile the device, identify targets of interest, or guide follow-on actions. It additionally supports deleting files from the device, a capability consistent with defense evasion or cleanup.
The malware is best characterized as Android surveillance malware with RAT functionality, combining remote control, on-device discovery, data theft, and limited destructive or concealment behaviors. The available facts support Android targeting and do not establish broader platform coverage.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
AbstractEmu can collect device IP address and SIM information; Android/SpyAgent has collected device network information, such as the IMEI and the phone number; ANDROIDOS_ANSERVER.A gathers the device IMEI and IMSI; many listed mobile malware families collect IMEI, IMSI, ICCID, MEID, serial number, phone number, MAC address, IP address, carrier, MCC/MNC, and related device/network identifiers.
Anubis can exfiltrate files encrypted with the ransomware module from the device and can modify external storage. BusyGasper can collect images stored on the device and browser history. CHEMISTGAMES can collect files from the filesystem and account information from Google Chrome.
PJApps has the capability to collect and leak the victim's phone number, mobile device unique identifier (IMEI); RedDrop collects and exfiltrates information including IMEI, IMSI, MNC, MCC, nearby Wi‑Fi networks, and other device and SIM-related info; Sunbird can exfiltrate phone number and IMEI; WolfRAT sends the device’s IMEI with each exfiltration request.
19 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android RAT capable of taking photos and videos.
Android remote access trojan that steals account data, photos, browser history, and arbitrary files.
Remote access trojan capable of obtaining a list of installed applications.
Android remote access trojan that impersonates Google services and Flash updates.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.