AhMyth
- First seen
- 2017-07-15 00:00:00
- Malware type
- rat, credential-stealer, screen-capture
- Family
- Malware family
- Last IoC activity
- 2026-06-16 12:41:17
- Profile updated
- 2026-07-07 13:08:40
Targeted industries: financial-services technology-and-telecommunications
Context
According to PCrisk, Ahmyth is a Remote Access Trojan (RAT) targeting Android users. It is distributed via trojanized (fake) applications. Ahmyth RAT steals cryptocurrency and banking credentials, 2FA codes, lock screen passcodes, and captures screenshots.
Reports & references
- deform.co — Hacker Group Caracal Kitten Targets Kdp Activists With Malware (report)
- malpedia.caad.fkie.fraunhofer.de — Apk.Ahmyth (report)
- Kaspersky — 98233 (report)
- stratosphereips.org — Android Mischief Rats Dataset (report)
- mp.weixin.qq.com — J A12Sox0K5Toyfaegbv W (report)
- secrss.com — 24995 (report)
- ESET — First Spyware Android Ahmyth Google Play (report)