HilalRAT
MITRE ATT&CK: S1128 View on attack.mitre.org
Aliases: HilalRAT
- First seen
- 2022-05-15 00:00:00
- Malware type
- rat
- Family
- Malware family
- Operating systems
- android
- Related IoCs
- 1 (1 malicious)
- Last IoC activity
- 2026-06-10 16:38:32
- Profile updated
- 2026-07-07 13:23:46
Targeted industries: government-and-public-sector education-and-nonprofits
Context
HilalRAT is a remote access-capable Android malware, developed and used by UNC788. HilalRAT is capable of collecting data, such as device location, call logs, etc., and is capable of executing actions, such as activating a device's camera and microphone.
Recent IoC activity
1 malicious indicator in Maltiverse are attributed to HilalRAT (S1128). The 1 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| file sample | 260607-p8bckaez9m.bin | 2026-06-10 | 1 |
Malware & tools used
- Contact List (attack-pattern)
- Stored Application Data (attack-pattern)
- Audio Capture (attack-pattern)
- SMS Messages (attack-pattern)
- Location Tracking (attack-pattern)
- Video Capture (attack-pattern)
Used by threat actors
- UNC788 (threat-actor)
Reports & references
- about.fb.com — Meta Quarterly Adversarial Threat Report Q1 2022 (report)
- malpedia.caad.fkie.fraunhofer.de — Apk.Hilalrat (report)
- thehackernews.com — Microsoft Obtains Court Order To Take (report)
- MITRE ATT&CK — S1128 (report)