AndroRAT

MITRE ATT&CK: S0292 View on attack.mitre.org

Aliases: AndroRAT

First seen
2012-11-25 00:00:00
Malware type
rat, spyware
Family
Malware family
Operating systems
android
Related IoCs
16 (16 malicious)
Last IoC activity
2026-08-19 17:59:33
Profile updated
2026-07-07 15:45:28

Context

AndroRAT is an open-source remote access tool for Android devices. AndroRAT is capable of collecting data, such as device location, call logs, etc., and is capable of executing actions, such as sending SMS messages and taking pictures. It is originally available through the `The404Hacking` Github repository.

Recent IoC activity

16 malicious indicators in Maltiverse are attributed to AndroRAT (S0292). The 16 most recently updated:

TypeIndicatorUpdatedSources
URL https://dosya.co/nytz7ag6fqr3/minecraft-1-18-2.apk.html 2026-08-19 1
file sample 347f1b018f643de0b9c946c94bd490a7426503869a0828b0a70b4d318fa097d6 2026-07-20 3
file sample gay.apk 2026-07-05 1
hostname aptabase.jesfeoqrj3.xyz 2026-06-16 1
file sample ZalithLauncherDependencies.apk 2026-06-07 1
file sample skibiditoiletgame.apk 2026-05-24 1
file sample MainOS.apk 2026-05-16 1
file sample 61afe61b5e5e7a74c00962142241caae6d4e5d44d97095b812624dae50d7f129 2026-04-15 1
file sample 8e56fb851e4bbda3005e72c4312f64a89ca1e53892b2060c452615ad3fd6b698 2026-04-14 1
file sample c346d7cc8dbc2f06aed5821ecb5490fb258749961c4f2b4a491599146e422b93 2026-04-12 1
file sample bb553e2e8bfc4bebb21552ed1068565f9609ad5dcc8fea58dc0ff1082c775df5 2026-04-11 1
file sample app.apk 2026-04-09 1
file sample 6478764346de677ed2a6f8c54daad96b6bdccb96449787c1db66a32f62175756 2026-03-31 1
file sample devil.apk 2026-03-21 1
file sample minecraft_launcher.apk 2026-02-12 1
file sample minecraft_launcher.apk 2026-02-12 1

Malware & tools used

  • SMS Control (attack-pattern)
  • Call Log (attack-pattern)
  • Video Capture (attack-pattern)
  • SMS Messages (attack-pattern)
  • Contact List (attack-pattern)
  • Audio Capture (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Match Legitimate Name or Location (attack-pattern)
  • Call Control (attack-pattern)
  • Location Tracking (attack-pattern)

Reports & references

  • bitdefender.com — Bitdefender Pr Whitepaper Bitterapt Creat4571 En En Genericuse (report)
  • Cisco Talos — Bitter Apt Adds Bangladesh To Their (report)
  • forcepoint.com — Bitter Targeted Attack Against Pakistan (report)
  • stratosphereips.org — Android Mischief Rats Dataset (report)
  • malpedia.caad.fkie.fraunhofer.de — Apk.Androrat (report)
  • github.com — Androrat (report)
  • hotforsecurity.bitdefender.com — Possibly Italy Born Android Rat Reported In China Find Bitdefender Researchers 16264 (report)
  • kaspersky.com — 24290 (report)
  • Trend Micro — The Urpage Connection To Bahamut Confucius And Patchwork (report)
  • cocomelonc.github.io — Aiya Mmd Book (report)
  • stratosphereips.org — Dissecting A Rat Analysis Of The Androrat (report)
  • mp.weixin.qq.com — Ahxp5Hmrotmsfbiuxj0Cfg (report)
  • stratosphereips.org — Dissecting A Rat Analysis Of The Command Line Androrat (report)
  • blog.lookout.com — Spoofed Apps (report)
  • MITRE ATT&CK — S0292 (report)
  • web.archive.org — Androrat (report)
  • latesthackingnews.com — How To Hack Android Phones With Androrat (report)
  • github.com — Androrat (report)

External references