AhRat
MITRE ATT&CK: S1095 View on attack.mitre.org
Aliases: AhRat
- First seen
- 2022-08-01 00:00:00
- Malware type
- rat
- Family
- Malware family
- Operating systems
- android
- Related IoCs
- 1 (1 malicious)
- Last IoC activity
- 2026-08-21 15:59:34
- Profile updated
- 2026-07-07 15:30:29
Targeted industries: media-and-entertainment
Context
AhRat is an Android remote access tool based on the open-source AhMyth remote access tool. AhRat initially spread in August 2022 on the Google Play Store via an update containing malicious code to the previously benign application, “iRecorder – Screen Recorder,” which itself was released in September 2021.
Recent IoC activity
1 malicious indicator in Maltiverse are attributed to AhRat (S1095). The 1 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| file sample | com.tsoft.app.iscreenrecorder.apk | 2026-08-21 | 1 |
Malware & tools used
- Web Protocols (attack-pattern)
- Data from Local System (attack-pattern)
- Exfiltration Over C2 Channel (attack-pattern)
- Contact List (attack-pattern)
- Boot or Logon Initialization Scripts (attack-pattern)
- Location Tracking (attack-pattern)
- Call Log (attack-pattern)
- Obfuscated Files or Information (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Encrypted Channel (attack-pattern)
- Screen Capture (attack-pattern)
- Audio Capture (attack-pattern)
- System Information Discovery (attack-pattern)
- Broadcast Receivers (attack-pattern)
- SMS Control (attack-pattern)
Reports & references
- MITRE ATT&CK — S1095 (report)
- ESET — Android App Breaking Bad Legitimate Screen Recording File Exfiltration (report)