The final malware is a modified version of the AhMyth Android RAT, open-source malware downloadable from GitHub, which is built by binding the malicious payload inside other legitimate applications.
AhMyth
AhMyth is an open-source Android remote access trojan used for surveillance and remote control of infected devices.
Profile source: Mallory opens in a new tabAhMyth
Family profile
AhMyth is an open-source Android remote access trojan used for surveillance and remote control of infected devices. Publicly available since the late 2010s, it has been widely reused, modified, and embedded into trojanized Android applications by both criminal operators and espionage actors. AhMyth has appeared in malicious apps distributed through official and third-party Android app stores, dedicated lure sites, social-media promotion, and repackaged applications that preserve benign functionality while covertly adding spyware features.
AhMyth is associated with Android-focused spying activity and supports collection of device data and user content. Reported capabilities across AhMyth and AhMyth-derived samples include theft of contacts and files, sending SMS messages, keylogging, screenshot capture, and interception of one-time passwords used for multi-factor authentication. Modified variants have added broader surveillance and post-compromise functionality such as continuous audio recording, deletion of selected SMS messages, downloading additional Android packages, and automated exfiltration of media, documents, messages, and application data.
The malware has been linked to multiple operational contexts. AhMyth-derived spyware has been observed in trojanized consumer-facing apps, including a music-streaming application that combined legitimate functionality with covert data theft and credential harvesting behavior. Customized AhMyth variants have also been used by Transparent Tribe against targets in India, including military and government personnel, delivered through themed Android lures and fake utility or entertainment apps. AhMyth’s code lineage has also influenced later Android malware projects, including frameworks inspired by or built from it.
AhMyth primarily targets Android devices and is best characterized as a commodity open-source RAT whose accessibility has enabled broad adoption, derivative development, and repeated use in espionage and surveillance campaigns.
Capabilities
- Credential Theft
- Exfiltration
- Keylogging
- Post Exploitation
Reported operators
Threat actors
1 named in public reportingMITRE ATT&CK