Last seven days
- First activity
- Jul 14, 2026
- Last activity
- Jul 14, 2026
- Feed role
- C2
- Host form
- 1 IP / 0 hostnames
AndroRAT is an open-source Android remote access trojan (RAT) used as a basis for multiple espionage-focused mobile implants.
Profile source: Mallory opens in a new tabAndroRAT
AndroRAT is an open-source Android remote access trojan (RAT) used as a basis for multiple espionage-focused mobile implants. The content states that AndroRAT can send SMS messages, capture SMS messages, collect call logs, collect contact list information, and obtain device location via GPS or network settings. It is also referenced as part of the tooling used by several threat actors and campaigns.
The malware is directly associated in the content with South Asian espionage activity. Transparent Tribe (APT36) began targeting Android in 2021 using a modified version of the open-source AndroRAT; Trend Micro named that modified implant CapraRAT. Multiple reports cited in the content describe CapraRAT as loosely based on AndroRAT source code or as a second-stage implant based on open-source AndroRAT. Transparent Tribe used these Android implants in targeted campaigns against Indian and Pakistani users, including likely military or political targets, distributing trojanized apps outside Google Play via fake websites and social-engineering lures. Patchwork is also described as having used a customized version of AndroRAT in recent attacks. Volexity further reported that EvilBamboo’s BADSOLAR downloaded a second-stage JAR based on the open-source AndroRAT project. Cisco Talos lists AndroRAT among Bitter’s known tooling, and Lookout notes Iranian APT groups have leveraged tools such as Metasploit, AndroRat, and AhMyth in campaigns.
High-confidence capabilities explicitly mentioned in the content include SMS sending, SMS capture, call-log collection, contact theft, and location collection. The content does not provide standalone AndroRAT-specific indicators of compromise, but it repeatedly identifies AndroRAT as the open-source foundation for later Android spyware variants such as CapraRAT and BADSOLAR second-stage implants.
C2 tracking
Derp observations, rolling seven-day window
Samples
Reported operators
In 2021, the group started to target the Android platform, using a modified version of an open-source RAT named AndroRAT. It bears similarities to CrimsonRAT, and has been named CapraRAT by Trend Micro in its research.
MITRE ATT&CK
Reporting
"These groups also leverage tools like Metasploit, AndroRat, and AhMyth in campaigns."
When the tool was initially named by Trend Micro, their research team noted that CapraRAT may be loosely based on the AndroRAT source code.
"The second-stage implant is based on the open-source AndroRAT..."
In 2021, the group started to target the Android platform, using a modified version of an open-source RAT named AndroRAT. It bears similarities to CrimsonRAT, and has been named CapraRAT by Trend Micro in its research.
"Their arsenal mainly contains Bitter RAT, Artra downloader, SlideRAT and AndroRAT."
AndroRAT can send SMS messages.
Patchwork has also recently employed Android malware in its attacks, with its use of a customized version of AndroRAT.
AndroRAT captures SMS messages.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.