HilalRAT

MITRE ATT&CK: S1128 View on attack.mitre.org

Aliases: HilalRAT

First seen
2022-05-15 00:00:00
Malware type
rat
Family
Malware family
Operating systems
android
Related IoCs
1 (1 malicious)
Last IoC activity
2026-06-10 16:38:32
Profile updated
2026-07-07 13:23:46

Targeted industries: government-and-public-sector education-and-nonprofits

Context

HilalRAT is a remote access-capable Android malware, developed and used by UNC788. HilalRAT is capable of collecting data, such as device location, call logs, etc., and is capable of executing actions, such as activating a device's camera and microphone.

Recent IoC activity

1 malicious indicator in Maltiverse are attributed to HilalRAT (S1128). The 1 most recently updated:

TypeIndicatorUpdatedSources
file sample 260607-p8bckaez9m.bin 2026-06-10 1

Malware & tools used

  • Contact List (attack-pattern)
  • Stored Application Data (attack-pattern)
  • Audio Capture (attack-pattern)
  • SMS Messages (attack-pattern)
  • Location Tracking (attack-pattern)
  • Video Capture (attack-pattern)

Used by threat actors

Reports & references

  • about.fb.com — Meta Quarterly Adversarial Threat Report Q1 2022 (report)
  • malpedia.caad.fkie.fraunhofer.de — Apk.Hilalrat (report)
  • thehackernews.com — Microsoft Obtains Court Order To Take (report)
  • MITRE ATT&CK — S1128 (report)

External references