BRATA
MITRE ATT&CK: S1094 View on attack.mitre.org
Aliases: AmexTroll, Copybara, BRATA
- First seen
- 2018-01-01 00:00:00
- Malware type
- rat
- Family
- Malware family
- Operating systems
- android
- Related IoCs
- 4 (4 malicious)
- Last IoC activity
- 2026-08-21 12:35:09
- Profile updated
- 2026-07-07 14:03:38
Targeted industries: financial-services
Targeted regions: country_code:br country_code:gb country_code:pl country_code:it country_code:es country_code:us
Context
BRATA (Brazilian Remote Access Tool, Android), is an evolving Android malware strain, detected in late 2018 and again in late 2021. Originating in Brazil, BRATA was later also found in the UK, Poland, Italy, Spain, and USA, where it is believed to have targeted financial institutions such as banks. There are currently three known variants of BRATA.
Recent IoC activity
4 malicious indicators in Maltiverse are attributed to BRATA (S1094). The 4 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| hostname | liveum.ga | 2026-08-21 | 1 |
| file sample | 27e0ec79dbb7c7f99b43c8c01a94188d1071d1245b1745d0e066ae774c78a8f8.apk | 2026-08-13 | 1 |
| hostname | umlive.ml | 2026-08-03 | 1 |
| file sample | f530c66fb1f7ac5e2e9a89c1f410e498dc59eecbec8bae29a9f69ab3dc7ce86c.zip | 2026-05-21 | 1 |
Detection coverage
- 1 YARA rules
Malware & tools used
- Download New Code at Runtime (attack-pattern)
- Location Tracking (attack-pattern)
- Uninstall Malicious Application (attack-pattern)
- Screen Capture (attack-pattern)
- Lockscreen Bypass (attack-pattern)
- Data Destruction (attack-pattern)
- Keylogging (attack-pattern)
- Transmitted Data Manipulation (attack-pattern)
- System Information Discovery (attack-pattern)
- Obfuscated Files or Information (attack-pattern)
- Disable or Modify Tools (attack-pattern)
- Geofencing (attack-pattern)
- Security Software Discovery (attack-pattern)
- System Checks (attack-pattern)
- Call Control (attack-pattern)
- Exfiltration Over C2 Channel (attack-pattern)
- Match Legitimate Name or Location (attack-pattern)
- User Evasion (attack-pattern)
- Web Protocols (attack-pattern)
- Input Injection (attack-pattern)
- Archive Collected Data (attack-pattern)
- Remote Access Software (attack-pattern)
- Exploitation for Initial Access (attack-pattern)
- GUI Input Capture (attack-pattern)
- Phishing (attack-pattern)
Detection rules
- SEKOIA_Trojan_Android_Brata (yara-rule)
Reports & references
- threatfabric.com — Brata A Tale Of Three Families (report)
- malpedia.caad.fkie.fraunhofer.de — Apk.Brata (report)
- threatfabric.com — Toad Fraud (report)
- Kaspersky — 92775 (report)
- advintel.io — Economic Growth Digital Inclusion Specialized Crime Financial Cyber Fraud In Latam (report)
- cleafy.com — Mobile Banking Fraud Brata Strikes Again (report)
- cleafy.com — Brata Is Evolving Into An Advanced Persistent Threat (report)
- cleafy.com — How Brata Is Monitoring Your Bank Account (report)
- MITRE ATT&CK — S1094 (report)
- McAfee — Brata Keeps Sneaking Into Google Play Now Targeting Usa And Spain (report)