AhMyth is an open-source Android remote access trojan used as both a standalone malware family and a foundation for customized mobile spyware. Publicly available since late 2017, it has been adopted and modified by multiple threat actors and criminal operators, including espionage campaigns linked to Transparent Tribe and malware embedded in trojanized Android applications distributed through official and third-party app stores, dedicated websites, and social-media promotion. AhMyth-derived implants have also appeared inside seemingly functional applications, including media, messaging, and themed lure apps.
AhMyth targets Android devices and provides remote surveillance and device-control capabilities. Reported functionality across AhMyth and modified variants includes theft of contacts, files, SMS data, and other device information; sending SMS messages; keylogging; screenshot capture; interception of one-time passwords used for MFA; audio recording; and broader exfiltration of user data. Some customized variants added startup persistence, retrieval of updated configuration from remote infrastructure, downloading of additional APK payloads, deletion of selected SMS messages, and automated collection of media, documents, and messaging-app content.
Operationally, AhMyth is commonly delivered through infected or trojanized Android apps masquerading as legitimate software. Documented lures include fake utility, entertainment, messaging, and topical applications, with distribution observed via Google Play, alternative app stores, GitHub-hosted projects, dedicated download sites, and messaging-based social engineering. Its open-source nature has made it a recurring building block in Android surveillance operations and commodity mobile malware ecosystems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The final malware is a modified version of the AhMyth Android RAT, open-source malware downloadable from GitHub, which is built by binding the malicious payload inside other legitimate applications.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
For C&C communication, Radio Balouch relies on its (now defunct) radiobalouch[.]com domain. This is where it would send information it has gathered about its victims... As with the account credentials, the C&C traffic is transmitted unencrypted over an HTTP connection.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Open-source/commodity Android RAT referenced as used in campaigns by Iranian APT groups.
Mobile RAT family listed among top mobile threats; described at a high level as offering remote access and other advanced capabilities (not broken out per-family).
An Android RAT referenced in the report as sharing C2-linked infrastructure with Transparent Tribe activity.
Android RAT delivered via infected apps; performs keylogging, screenshot capture, and OTP interception to bypass MFA.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.