Last seven days
- First activity
- Aug 28, 2026
- Last activity
- Sep 1, 2026
- Feed role
- C2 / Distribution
- Host form
- 0 IP / 11 hostnames
IRATA is an Android remote access Trojan and banking malware family targeting victims in Iran.
Profile source: Mallory opens in a new tabIrata
IRATA is an Android remote access Trojan and banking malware family targeting victims in Iran. It is distributed via SMS phishing campaigns that impersonate government services or other trusted entities and lure users into downloading a malicious APK; earlier observed variants also impersonated an Arabic-language stock market app, and later versions were reported impersonating official Iranian organizations. The malware steals SMS messages, credit card and banking-related data, contacts, and device information, and can intercept SMS-based two-factor authentication codes. It also turns infected devices into bots that propagate additional phishing SMS to other potential victims.
Observed capabilities include reading, receiving, and sending SMS; collecting contacts; gathering device and SIM identifiers such as device ID, SIM serial number, line number, and subscriber ID; monitoring phone and device events including screen state, shutdown, battery state, airplane mode, and package installation/removal; altering ringer mode and volume via commands such as vibrate, silent, and normal; and hiding its app icon for persistence. The malware registers components to handle BOOT_COMPLETED and SMS_RECEIVED, and can observe outgoing SMS activity via content://sms. Reported command support includes ping, pingone, SendSingleMessage, getdevicefullinfo, hideicon, showhideicon, testphone, getsms, and getcontact.
IRATA uses Firebase Cloud Messaging as a command-and-control channel. Stolen SMS data is written to AllSms.txt and uploaded to remote infrastructure, while stolen contacts are written to Contacts.txt and similarly exfiltrated. Reported infrastructure includes usenlghusk.gq with paths /USK/rat.php and /USK/upload.php. The APK was reported to request permissions including INTERNET, READ_SMS, RECEIVE_SMS, SEND_SMS, READ_CONTACTS, RECEIVE_BOOT_COMPLETED, and com.google.android.c2dm.permission.RECEIVE, and to define the package-specific permission ir.shz.shzkisi.permission.C2D_MESSAGE. A reported sample MD5 is ce41d55ee66d509e1e2043d9e238f65a.
Additional reporting states that IRATA has been observed targeting more than 50 banking and cryptocurrency apps and abusing Android accessibility services to steal bank account numbers, balances, and card data.
Samples
6009c26b36f2d24db01da41bd2250b07bfae6da238cb578622c19ad01075ea19 8b10d29548d66e9ff9d9241505e09b24425e38453991a41ea3836ca2c3223a06 ffd29c57df2fb49013dfad0cf4182921e6ec36df41d69a4cb7838b09a4ba779b fe1a6cfa58b501b49ba1c3c9b857685e7919d9e124ae1f2f4f23625fee651a62 9d105edc4e3a53b342968fe805769342b15c3068100bcbdf22bc2e8b77f906d1 f670c1cb8304b48a5ed2fa37e7e2f78d382ab82ddbfb66733c04aeb1d576efbc b7822b99492aef3e51cc1761ec653508765154b18d04bf600ebbb3587fdf6dc5 bd8c0ec3b4af54e4939a756de9664ea019237d4141d51c2522ea4a5dc7f3d233 ce62915cc96735d1921613c9969882e352429c7aaab54145d270502d6b6068d2 d21b06d6862a661685a1e3a135477935d72903bd957175d113bfbba011db76b2 MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.