AhRat
AhRat is a mobile malware family with Android-focused surveillance and data theft capabilities.
Profile source: Mallory opens in a new tabAhRat
Family profile
AhRat is a mobile malware family with Android-focused surveillance and data theft capabilities. Based on the provided content, it can send SMS messages; collect the device’s contact list and call log; obtain device information including manufacturer, device ID, OS version, and country; locate and exfiltrate files with extensions such as .jpg, .mp4, .html, .docx, and .pdf; and exfiltrate collected data including audio recordings and files to command-and-control infrastructure. Its C2 communications use HTTPS requests. No specific threat actor, campaign association, targeted industry, or concrete indicators of compromise are provided in the content.
MITRE ATT&CK