RatMilad
MITRE ATT&CK: S1241 View on attack.mitre.org
Aliases: RatMilad
- First seen
- 2021-01-01 00:00:00
- Malware type
- rat, spyware
- Family
- Malware family
- Operating systems
- android
- Profile updated
- 2026-07-07 14:09:16
Targeted industries: government-and-public-sector technology-and-telecommunications
Targeted regions: country_code:sa country_code:ae
Context
RatMilad is an Android remote access tool (RAT) with spyware functionality that has been used to target enterprise mobile devices in the Middle East since at least 2021. Variants of RatMilad have been disguised as VPN applications and a fake app named NumRent. Upon installation, RatMilad employs multiple Collection techniques to collect sensitive information before uploading the collected data to its command and control (C2) server.
Malware & tools used
- Call Log (attack-pattern)
- Accounts (attack-pattern)
- Software Discovery (attack-pattern)
- Phishing (attack-pattern)
- Contact List (attack-pattern)
- Web Protocols (attack-pattern)
- Clipboard Data (attack-pattern)
- Data from Local System (attack-pattern)
- Exfiltration Over C2 Channel (attack-pattern)
- Download New Code at Runtime (attack-pattern)
- Location Tracking (attack-pattern)
- System Information Discovery (attack-pattern)
- SMS Messages (attack-pattern)
- Video Capture (attack-pattern)
- Data Destruction (attack-pattern)
- Audio Capture (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- File and Directory Discovery (attack-pattern)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Apk.Ratmilad (report)
- socradar.io — New Spyware Ratmilad Targets Middle Eastern Mobile Devices (report)
- MITRE ATT&CK — S1241 (report)
- zimperium.com — We Smell A Ratmilad Mobile Spyware (report)