HyperRat operators are the threat actors behind HyperRat, an Android remote access trojan associated with mobile-device compromise for data theft and interactive remote control. The activity has been linked to deployment of Android malware capable of stealing sensitive information from infected devices and enabling remote access functions including virtual network computing sessions. Based on the available facts, the operators are best characterized as cybercriminal malware operators focused on post-compromise control and theft from Android users. No high-confidence attribution to a specific named intrusion set, country of origin, or broader organizational structure is currently available.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.