AhMyth
AhMyth is an Android remote access trojan (RAT) and open-source malware available on GitHub. The provided content describes it as being distributed through infected Android applications on various app stores and as capable of keylogging, taking screenshots, and intercepting SMS-based one-time passwords (OTPs) used for MFA bypass. AhMyth is also referenced as a tool leveraged in campaigns by multiple threat actors, including Transparent Tribe and Iranian APT activity more broadly. One report states that the IP address 173.249.50.243 had been tied to Transparent Tribe’s CrimsonRAT and AhMyth Android RAT command-and-control activity since at least 2022. The content also notes AhMyth among the top mobile malware families in April 2025 and mentions a modified version of AhMyth being used in the wild.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Groups observed using it
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
This IP address has been tied to Transparent Tribe’s CrimsonRAT and AhMyth Android RAT C2 activity since at least 2022.
“a modified version of the AhMyth Android RAT which is open source malware available on GitHub.”
Recent activity
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Open-source/commodity Android RAT referenced as used in campaigns by Iranian APT groups.
Mobile RAT family listed among top mobile threats; described at a high level as offering remote access and other advanced capabilities (not broken out per-family).
An Android RAT referenced in the report as sharing C2-linked infrastructure with Transparent Tribe activity.
Android RAT delivered via infected apps; performs keylogging, screenshot capture, and OTP interception to bypass MFA.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.