Skip to content

AhRat

AhRat is a mobile malware family with Android-focused surveillance and data theft capabilities.

Profile source: Mallory opens in a new tab

AhRat

Family profile

AhRat is a mobile malware family with Android-focused surveillance and data theft capabilities. Based on the provided content, it can send SMS messages; collect the device’s contact list and call log; obtain device information including manufacturer, device ID, OS version, and country; locate and exfiltrate files with extensions such as .jpg, .mp4, .html, .docx, and .pdf; and exfiltrate collected data including audio recordings and files to command-and-control infrastructure. Its C2 communications use HTTPS requests. No specific threat actor, campaign association, targeted industry, or concrete indicators of compromise are provided in the content.

Observed infrastructure

Last seven days

First activity
Jul 28, 2026
Last activity
Jul 28, 2026
Feed role
C2
Host form
0 IP / 2 hostnames

MITRE ATT&CK

AhRat in ATT&CK

3 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.