Bitter (aka APT-C-08 or T-APT-17) is suspected to be a South Asian hacking group motivated primarily by intelligence gathering, an operation that's facilitated by means of malware such as BitterRAT, ArtraDownloader, and AndroRAT.
AndroRAT
AndroRAT is an open-source Android remote access trojan implemented as a Java-based client/server application, with an Android client and a Java/Swing operator console.
Profile source: Mallory opens in a new tabAndroRAT
Family profile
AndroRAT is an open-source Android remote access trojan implemented as a Java-based client/server application, with an Android client and a Java/Swing operator console. The client can run as a background service, start at device boot, and establish or activate communications following SMS or telephone-call triggers. It supports remote surveillance and device control, including collection of contacts, call logs, SMS messages, device and network details, location data, and Wi-Fi credentials; microphone and call recording; camera capture; screen capture; SMS monitoring, deletion, and sending; phone calls; file transfer; and shell-command execution. Some variants hide their application icon, abuse Android accessibility services for keylogging, and exploit CVE-2015-1805 to gain elevated privileges on vulnerable Android devices. AndroRAT has been used or customized in espionage activity associated with Bitter, ITG18, and Patchwork. Transparent Tribe adapted its codebase into the Android backdoor known as CapraRAT. Android devices are commonly targeted through trojanized applications and social-engineering lures distributed outside official app stores.
Capabilities
- Credential Theft
- Defense Evasion
- Exfiltration
- Keylogging
- Persistence
- Post Exploitation
- Privilege Escalation
- Reconnaissance
Reported operators
Threat actors
4 named in public reportingAndroRAT – Open-source Android RAT
Patchwork has also recently employed Android malware in its attacks, with its use of a customized version of AndroRAT.
In 2021, the group started to target the Android platform, using a modified version of an open-source RAT named AndroRAT. It bears similarities to CrimsonRAT, and has been named CapraRAT by Trend Micro in its research.
Exploited software
Vulnerabilities linked to AndroRAT
4 CVEsMITRE ATT&CK
AndroRAT in ATT&CK
23 distinct techniquesTechniques
23 techniquesReporting
Research mentioning AndroRAT
Cyble - Fake Income Tax Application Targets Indian Taxpayers
Researchers identified an Android malware app named iMobile that impersonates India’s Income Tax Department and targets Indian taxpayers through phishing, harvesting sensitive data including PAN, Aadhaar, bank account information, debit card details, and internet banking credentials. The app also seeks extensive dangerous permissions and attempts to set itself as the device’s default SMS application, giving it the ability to read, receive, and send text messages while monitoring phone state and usage data. Analysis showed the stolen banking and internet-banking information was uploaded to the command-and-control endpoint jsig.quicksytes[.]com/MC/NN180521/mc.php, and the sample used string deobfuscation and hardcoded artifacts including an Indian mobile number. The campaign reflects a broader mobile threat pattern documented in MITRE ATT&CK T1636.004, where malicious apps abuse SMS access to intercept messages, including one-time passcodes and transaction alerts, to support credential theft, financial fraud, and account takeover.