BRATA

MITRE ATT&CK: S1094 View on attack.mitre.org

Aliases: AmexTroll, Copybara, BRATA

First seen
2018-01-01 00:00:00
Malware type
rat
Family
Malware family
Operating systems
android
Related IoCs
4 (4 malicious)
Last IoC activity
2026-08-21 12:35:09
Profile updated
2026-07-07 14:03:38

Targeted industries: financial-services

Targeted regions: country_code:br country_code:gb country_code:pl country_code:it country_code:es country_code:us

Context

BRATA (Brazilian Remote Access Tool, Android), is an evolving Android malware strain, detected in late 2018 and again in late 2021. Originating in Brazil, BRATA was later also found in the UK, Poland, Italy, Spain, and USA, where it is believed to have targeted financial institutions such as banks. There are currently three known variants of BRATA.

Recent IoC activity

4 malicious indicators in Maltiverse are attributed to BRATA (S1094). The 4 most recently updated:

TypeIndicatorUpdatedSources
hostname liveum.ga 2026-08-21 1
file sample 27e0ec79dbb7c7f99b43c8c01a94188d1071d1245b1745d0e066ae774c78a8f8.apk 2026-08-13 1
hostname umlive.ml 2026-08-03 1
file sample f530c66fb1f7ac5e2e9a89c1f410e498dc59eecbec8bae29a9f69ab3dc7ce86c.zip 2026-05-21 1

Detection coverage

  • 1 YARA rules

Malware & tools used

  • Download New Code at Runtime (attack-pattern)
  • Location Tracking (attack-pattern)
  • Uninstall Malicious Application (attack-pattern)
  • Screen Capture (attack-pattern)
  • Lockscreen Bypass (attack-pattern)
  • Data Destruction (attack-pattern)
  • Keylogging (attack-pattern)
  • Transmitted Data Manipulation (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Obfuscated Files or Information (attack-pattern)
  • Disable or Modify Tools (attack-pattern)
  • Geofencing (attack-pattern)
  • Security Software Discovery (attack-pattern)
  • System Checks (attack-pattern)
  • Call Control (attack-pattern)
  • Exfiltration Over C2 Channel (attack-pattern)
  • Match Legitimate Name or Location (attack-pattern)
  • User Evasion (attack-pattern)
  • Web Protocols (attack-pattern)
  • Input Injection (attack-pattern)
  • Archive Collected Data (attack-pattern)
  • Remote Access Software (attack-pattern)
  • Exploitation for Initial Access (attack-pattern)
  • GUI Input Capture (attack-pattern)
  • Phishing (attack-pattern)

Detection rules

  • SEKOIA_Trojan_Android_Brata (yara-rule)

Reports & references

  • threatfabric.com — Brata A Tale Of Three Families (report)
  • malpedia.caad.fkie.fraunhofer.de — Apk.Brata (report)
  • threatfabric.com — Toad Fraud (report)
  • Kaspersky — 92775 (report)
  • advintel.io — Economic Growth Digital Inclusion Specialized Crime Financial Cyber Fraud In Latam (report)
  • cleafy.com — Mobile Banking Fraud Brata Strikes Again (report)
  • cleafy.com — Brata Is Evolving Into An Advanced Persistent Threat (report)
  • cleafy.com — How Brata Is Monitoring Your Bank Account (report)
  • MITRE ATT&CK — S1094 (report)
  • McAfee — Brata Keeps Sneaking Into Google Play Now Targeting Usa And Spain (report)

External references