Last seven days
- First activity
- Jul 23, 2026
- Last activity
- Jul 23, 2026
- Feed role
- C2
- Host form
- 0 IP / 4 hostnames
PlayPraetor is an Android remote access trojan (RAT) described as an evolving on-device malware threat.
Profile source: Mallory opens in a new tabPlayPraetor
PlayPraetor is an Android remote access trojan (RAT) described as an evolving on-device malware threat. Reporting states it was launched in 2025 by Chinese-speaking developers/actors and is offered via a malware-as-a-service model, enabling global scaling of operations. It has been reported to infect more than 11,000 Android devices and has been observed targeting users across all major continents, with noted expansion in Spanish- and French-speaking regions. Documented capabilities include launching phishing attacks and stealing credentials from more than 200 applications. The available content associates PlayPraetor with Chinese-speaking operators but does not provide a more specific threat actor attribution. No high-confidence technical indicators of compromise are provided in the supplied content.
Samples
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.