Skip to content

AndroRAT

AndroRAT is an open-source Android remote access trojan implemented as a Java-based client/server application, with an Android client and a Java/Swing operator console.

Profile source: Mallory opens in a new tab

AndroRAT

Family profile

AndroRAT is an open-source Android remote access trojan implemented as a Java-based client/server application, with an Android client and a Java/Swing operator console. The client can run as a background service, start at device boot, and establish or activate communications following SMS or telephone-call triggers. It supports remote surveillance and device control, including collection of contacts, call logs, SMS messages, device and network details, location data, and Wi-Fi credentials; microphone and call recording; camera capture; screen capture; SMS monitoring, deletion, and sending; phone calls; file transfer; and shell-command execution. Some variants hide their application icon, abuse Android accessibility services for keylogging, and exploit CVE-2015-1805 to gain elevated privileges on vulnerable Android devices. AndroRAT has been used or customized in espionage activity associated with Bitter, ITG18, and Patchwork. Transparent Tribe adapted its codebase into the Android backdoor known as CapraRAT. Android devices are commonly targeted through trojanized applications and social-engineering lures distributed outside official app stores.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Keylogging
  • Persistence
  • Post Exploitation
  • Privilege Escalation
  • Reconnaissance

Reported operators

Threat actors

4 named in public reporting
Bitter

Bitter (aka APT-C-08 or T-APT-17) is suspected to be a South Asian hacking group motivated primarily by intelligence gathering, an operation that's facilitated by means of malware such as BitterRAT, ArtraDownloader, and AndroRAT.

Patchwork

Patchwork has also recently employed Android malware in its attacks, with its use of a customized version of AndroRAT.

Transparent Tribe

In 2021, the group started to target the Android platform, using a modified version of an open-source RAT named AndroRAT. It bears similarities to CrimsonRAT, and has been named CapraRAT by Trend Micro in its research.

Exploited software

Vulnerabilities linked to AndroRAT

4 CVEs

MITRE ATT&CK

AndroRAT in ATT&CK

23 distinct techniques

Reporting

Research mentioning AndroRAT

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.