Skip to content
Malware family

PlayPraetor

PlayPraetor is an Android remote access trojan (RAT) described as an evolving on-device malware threat.

Profile source: Mallory opens in a new tab

PlayPraetor

Family profile

PlayPraetor is an Android remote access trojan (RAT) described as an evolving on-device malware threat. Reporting states it was launched in 2025 by Chinese-speaking developers/actors and is offered via a malware-as-a-service model, enabling global scaling of operations. It has been reported to infect more than 11,000 Android devices and has been observed targeting users across all major continents, with noted expansion in Spanish- and French-speaking regions. Documented capabilities include launching phishing attacks and stealing credentials from more than 200 applications. The available content associates PlayPraetor with Chinese-speaking operators but does not provide a more specific threat actor attribution. No high-confidence technical indicators of compromise are provided in the supplied content.

Observed infrastructure

Last seven days

First activity
Jul 23, 2026
Last activity
Jul 23, 2026
Feed role
C2
Host form
0 IP / 4 hostnames

Samples

Recent associated samples

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.