RatMilad

MITRE ATT&CK: S1241 View on attack.mitre.org

Aliases: RatMilad

First seen
2021-01-01 00:00:00
Malware type
rat, spyware
Family
Malware family
Operating systems
android
Profile updated
2026-07-07 14:09:16

Targeted industries: government-and-public-sector technology-and-telecommunications

Targeted regions: country_code:sa country_code:ae

Context

RatMilad is an Android remote access tool (RAT) with spyware functionality that has been used to target enterprise mobile devices in the Middle East since at least 2021. Variants of RatMilad have been disguised as VPN applications and a fake app named NumRent. Upon installation, RatMilad employs multiple Collection techniques to collect sensitive information before uploading the collected data to its command and control (C2) server.

Malware & tools used

  • Call Log (attack-pattern)
  • Accounts (attack-pattern)
  • Software Discovery (attack-pattern)
  • Phishing (attack-pattern)
  • Contact List (attack-pattern)
  • Web Protocols (attack-pattern)
  • Clipboard Data (attack-pattern)
  • Data from Local System (attack-pattern)
  • Exfiltration Over C2 Channel (attack-pattern)
  • Download New Code at Runtime (attack-pattern)
  • Location Tracking (attack-pattern)
  • System Information Discovery (attack-pattern)
  • SMS Messages (attack-pattern)
  • Video Capture (attack-pattern)
  • Data Destruction (attack-pattern)
  • Audio Capture (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • File and Directory Discovery (attack-pattern)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Apk.Ratmilad (report)
  • socradar.io — New Spyware Ratmilad Targets Middle Eastern Mobile Devices (report)
  • MITRE ATT&CK — S1241 (report)
  • zimperium.com — We Smell A Ratmilad Mobile Spyware (report)

External references