CapraRAT
- First seen
- 2020-06-01 00:00:00
- Malware type
- rat
- Family
- Malware family
- Profile updated
- 2026-07-07 12:47:49
Targeted industries: government-and-public-sector defense-and-aerospace
Targeted regions: country_code:pk country_code:in
Context
According to PCrisk, CapraRAT is the name of an Android remote access trojan (RAT), possibly a modified version of another (open-source) RAT called AndroRAT. It is known that CapraRAT is used by an advanced persistent threat group (ATP) called APT36 (also known as Earth Karkaddan). CapraRAT allows attackers to perform certain actions on the infected Android device.
Reports & references
- Trend Micro — Investigating Apt36 Or Earth Karkaddans Attack Chain And Malware (report)
- sentinelone.com — Capratube Transparent Tribes Caprarat Mimics Youtube To Hijack Android Phones (report)
- malpedia.caad.fkie.fraunhofer.de — Apk.Capra Rat (report)
- ESET — Love Scam Espionage Transparent Tribe Lures Indian Pakistani Officials (report)