DroidJack, also known as SandroRAT, is an Android remote access trojan used to obtain near-complete remote control of infected mobile devices. It has been distributed through trojanized Android applications that masquerade as popular or legitimate software, including repackaged game-themed lures and fake utility or update apps, typically relying on users to sideload malicious APKs from outside trusted app stores. The malware has also appeared in targeted intrusion activity against Syrian opposition figures, where it was delivered as part of a broader multi-platform operation with Iran nexus indicators.
Once installed, DroidJack supports extensive surveillance and data theft from Android devices. Documented capabilities include capturing SMS data, harvesting call logs and call-related data, recording device phone calls, extracting WhatsApp data, and using the device camera to capture video. Reporting also attributes broader remote-administration and spying functionality to DroidJack, including effective full control of the victim phone and, in some campaigns, theft of contacts, file browsing, location tracking, and remote activation of camera and microphone functions. Collected data may be staged locally before transmission to command-and-control infrastructure.
DroidJack is notable for masquerading as legitimate applications by embedding or repackaging benign app code so the malicious APK appears authentic to the victim. Observed lures have exploited demand around high-profile mobile games and fake software updates to drive installation. The malware is primarily associated with Android surveillance, espionage, and criminal abuse scenarios rather than destructive activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"The APK is an instance of DroidJack. According to Symantec, this malware evolved from an older codebase known as SandroRAT."
11 distinct techniques documented for this family, organized by ATT&CK tactic.
DroidJack RAT starts capturing sensitive information like call data, SMS data, videos, photos, etc... Upon further inspection, we have observed that this RAT extracts WhatsApp data too.
The RAT stores all the data in a database (DB) in order to send it to the Command & Control (C&C) server. We saw the following hardcoded C&C server location in the RAT package.
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android RAT masquerading as an Adobe Flash Player update APK; hides its icon, persists via boot receiver, and enables extensive device surveillance (SMS/calls/contacts/files/location, remote camera/mic; some features require root). Configured to use 88.198.222[.]163 for C2.
Android remote access trojan disguised as a Super Mario Run app. Once installed, it registers the infected device, captures call data, SMS data, videos, photos, records calls to .amr files, captures video to .3gp files, extracts WhatsApp data, stores stolen data in local databases, and sends it to a hardcoded C2 server.
Android malware that can capture video through device cameras.
Android remote access trojan that repackages legitimate app code to appear authentic while adding malicious functionality.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.