Skip to content

AhRat

AhRat is an Android remote access trojan used for surveillance and data theft on compromised mobile devices.

Profile source: Mallory opens in a new tab

AhRat

Family profile

AhRat is an Android remote access trojan used for surveillance and data theft on compromised mobile devices. Its observed functionality includes collecting device profiling information such as manufacturer, device identifier, operating system version, and country; harvesting sensitive user data including contact lists and call logs; sending SMS messages; and locating and exfiltrating files of interest, including common media and document formats. AhRat also exfiltrates collected material such as audio recordings and files to command-and-control infrastructure and communicates with its operators over HTTPS. For persistence and event-triggered execution, it can register Android broadcast receivers for connectivity-related events, allowing additional functionality to be activated when network state changes. The malware is therefore characterized by a combination of mobile surveillance, data collection, exfiltration, and Android-specific persistence mechanisms.

Capabilities

  • Exfiltration
  • Persistence
  • Reconnaissance

MITRE ATT&CK

AhRat in ATT&CK

3 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.