WolfRAT

MITRE ATT&CK: S0489 View on attack.mitre.org

Aliases: WolfRAT

First seen
2019-04-01 00:00:00
Malware type
rat
Family
Malware family
Operating systems
android
Profile updated
2026-07-07 14:20:54

Targeted industries: government-and-public-sector

Targeted regions: country_code:th

Context

WolfRAT is malware based on a leaked version of Dendroid that has primarily targeted Thai users. WolfRAT has most likely been operated by the now defunct organization Wolf Research.

Malware & tools used

  • System Network Configuration Discovery (attack-pattern)
  • Call Log (attack-pattern)
  • File Deletion (attack-pattern)
  • Software Discovery (attack-pattern)
  • Audio Capture (attack-pattern)
  • Video Capture (attack-pattern)
  • Screen Capture (attack-pattern)
  • SMS Messages (attack-pattern)
  • SMS Control (attack-pattern)
  • Contact List (attack-pattern)
  • Data from Local System (attack-pattern)
  • Match Legitimate Name or Location (attack-pattern)
  • System Checks (attack-pattern)
  • Obfuscated Files or Information (attack-pattern)
  • Process Discovery (attack-pattern)
  • Download New Code at Runtime (attack-pattern)
  • Access Notifications (attack-pattern)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Apk.Wolf Rat (report)
  • Cisco Talos — The Wolf Is Back (report)
  • Cisco Talos — 2020 Year In Malware (report)
  • MITRE ATT&CK — S0489 (report)

External references