In 2021, the group started to target the Android platform, using a modified version of an open-source RAT named AndroRAT. It bears similarities to CrimsonRAT, and has been named CapraRAT by Trend Micro in its research.
AndroRAT
AndroRAT is an open-source Android remote access trojan (RAT) used as a basis for multiple espionage-focused mobile implants.
Profile source: Mallory opens in a new tabAndroRAT
Family profile
AndroRAT is an open-source Android remote access trojan (RAT) used as a basis for multiple espionage-focused mobile implants. The content states that AndroRAT can send SMS messages, capture SMS messages, collect call logs, collect contact list information, and obtain device location via GPS or network settings. It is also referenced as part of the tooling used by several threat actors and campaigns.
The malware is directly associated in the content with South Asian espionage activity. Transparent Tribe (APT36) began targeting Android in 2021 using a modified version of the open-source AndroRAT; Trend Micro named that modified implant CapraRAT. Multiple reports cited in the content describe CapraRAT as loosely based on AndroRAT source code or as a second-stage implant based on open-source AndroRAT. Transparent Tribe used these Android implants in targeted campaigns against Indian and Pakistani users, including likely military or political targets, distributing trojanized apps outside Google Play via fake websites and social-engineering lures. Patchwork is also described as having used a customized version of AndroRAT in recent attacks. Volexity further reported that EvilBamboo’s BADSOLAR downloaded a second-stage JAR based on the open-source AndroRAT project. Cisco Talos lists AndroRAT among Bitter’s known tooling, and Lookout notes Iranian APT groups have leveraged tools such as Metasploit, AndroRat, and AhMyth in campaigns.
High-confidence capabilities explicitly mentioned in the content include SMS sending, SMS capture, call-log collection, contact theft, and location collection. The content does not provide standalone AndroRAT-specific indicators of compromise, but it repeatedly identifies AndroRAT as the open-source foundation for later Android spyware variants such as CapraRAT and BADSOLAR second-stage implants.
Reported operators
Threat actors
1 named in public reportingMITRE ATT&CK
AndroRAT in ATT&CK
1 distinct techniquesTechniques
1 techniqueReporting
Research mentioning AndroRAT
MuddyWater deploys new DCHSpy variants amid Iran-Israel conflict
"These groups also leverage tools like Metasploit, AndroRat, and AhMyth in campaigns."
CapraTube | Transparent Tribe’s CapraRAT Mimics YouTube to Hijack Android Phones | SentinelOne
When the tool was initially named by Trend Micro, their research team noted that CapraRAT may be loosely based on the AndroRAT source code.
EvilBamboo Targets Mobile Devices in Multi-year Campaign | Volexity
"The second-stage implant is based on the open-source AndroRAT..."
Love scam or espionage? Transparent Tribe lures Indian and Pakistani officials
In 2021, the group started to target the Android platform, using a modified version of an open-source RAT named AndroRAT. It bears similarities to CrimsonRAT, and has been named CapraRAT by Trend Micro in its research.
Bitter APT adds Bangladesh to their targets
"Their arsenal mainly contains Bitter RAT, Artra downloader, SlideRAT and AndroRAT."
SMS Control, Technique T1582 - Mobile | MITRE ATT&CK®
AndroRAT can send SMS messages.
Bahamut, Confucius and Patchwork Connected to Urpage
Patchwork has also recently employed Android malware in its attacks, with its use of a customized version of AndroRAT.
Protected User Data: SMS Messages, Sub-technique T1636.004 - Mobile | MITRE ATT&CK®
AndroRAT captures SMS messages.