AhRat

MITRE ATT&CK: S1095 View on attack.mitre.org

Aliases: AhRat

First seen
2022-08-01 00:00:00
Malware type
rat
Family
Malware family
Operating systems
android
Related IoCs
1 (1 malicious)
Last IoC activity
2026-08-21 15:59:34
Profile updated
2026-07-07 15:30:29

Targeted industries: media-and-entertainment

Context

AhRat is an Android remote access tool based on the open-source AhMyth remote access tool. AhRat initially spread in August 2022 on the Google Play Store via an update containing malicious code to the previously benign application, “iRecorder – Screen Recorder,” which itself was released in September 2021.

Recent IoC activity

1 malicious indicator in Maltiverse are attributed to AhRat (S1095). The 1 most recently updated:

TypeIndicatorUpdatedSources
file sample com.tsoft.app.iscreenrecorder.apk 2026-08-21 1

Malware & tools used

  • Web Protocols (attack-pattern)
  • Data from Local System (attack-pattern)
  • Exfiltration Over C2 Channel (attack-pattern)
  • Contact List (attack-pattern)
  • Boot or Logon Initialization Scripts (attack-pattern)
  • Location Tracking (attack-pattern)
  • Call Log (attack-pattern)
  • Obfuscated Files or Information (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Encrypted Channel (attack-pattern)
  • Screen Capture (attack-pattern)
  • Audio Capture (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Broadcast Receivers (attack-pattern)
  • SMS Control (attack-pattern)

Reports & references

  • MITRE ATT&CK — S1095 (report)
  • ESET — Android App Breaking Bad Legitimate Screen Recording File Exfiltration (report)

External references