AhRat
AhRat is an Android remote access trojan used for surveillance and data theft on compromised mobile devices.
Profile source: Mallory opens in a new tabAhRat
Family profile
AhRat is an Android remote access trojan used for surveillance and data theft on compromised mobile devices. Its observed functionality includes collecting device profiling information such as manufacturer, device identifier, operating system version, and country; harvesting sensitive user data including contact lists and call logs; sending SMS messages; and locating and exfiltrating files of interest, including common media and document formats. AhRat also exfiltrates collected material such as audio recordings and files to command-and-control infrastructure and communicates with its operators over HTTPS. For persistence and event-triggered execution, it can register Android broadcast receivers for connectivity-related events, allowing additional functionality to be activated when network state changes. The malware is therefore characterized by a combination of mobile surveillance, data collection, exfiltration, and Android-specific persistence mechanisms.
Capabilities
- Exfiltration
- Persistence
- Reconnaissance
MITRE ATT&CK