OmniRAT is a commercially sold, multiplatform remote administration tool used maliciously to obtain full remote control of compromised devices. It supports Android, Windows, Linux, and macOS, and has been observed in criminal campaigns targeting Android users through social engineering. On Android, OmniRAT has been distributed via SMS-based lures that impersonate MMS or security-related notifications and trick victims into downloading and installing a malicious application package from an external link. Customized Android variants have also included propagation features that send additional SMS messages from infected devices to trusted contacts.
Once installed on Android, OmniRAT can provide extensive surveillance and device-control functionality. Reported capabilities include reading contacts and call logs, sending SMS messages, making calls, recording audio, retrieving service and process information, viewing or deleting browsing history, executing commands, and maintaining covert access even after the visible launcher icon is removed. The malware has been associated with exfiltration of victim data to attacker-controlled infrastructure.
OmniRAT is also notable as the basis for GhostCtrl, an Android backdoor variant or spinoff that expanded on OmniRAT-derived functionality with stronger obfuscation, broader device control, data theft, covert audio and video capture, and ransomware-like device locking behavior. This relationship underscores OmniRAT’s role not only as a standalone remote access tool but also as a foundation for further Android malware development.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Commercial multiplatform RAT from which GhostCtrl is described as a variant or spinoff.
A cross-platform remote access trojan/remote administration tool used by criminals to gain full remote control of Android, Windows, Linux, and Mac devices. In the described campaign, it is delivered via SMS lure and malicious APK, steals device data, records activity, persists after the lure app is removed, and can send SMS messages to spread further.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.