AndroRAT is an open-source Android remote administration framework widely repurposed as a remote access trojan for surveillance and espionage. Originally developed as a university project, it uses a Java Android client and a Java/Swing server interface. The Android client runs as a background service, starts at device boot, and supports connections triggered by SMS messages or telephone calls.
Its core capabilities include collecting contacts, call logs, and SMS messages; tracking GPS or network-based location; monitoring messages and call activity; taking photographs; and streaming microphone audio. Operators can also send SMS messages, place calls, and remotely interact with the device. Malicious deployments use deceptive Android applications and phishing lures, including religious and news-themed disguises.
An enhanced variant exploits CVE-2015-1805 to obtain root privileges on vulnerable Android devices. Its additional capabilities include shell-command execution, silent application installation, screen capture, telephone-call recording, file theft, browser-history collection, and Wi-Fi-password theft. It can silently enable accessibility services for keylogging, send forged SMS messages, and hide its application icon while continuing to operate in the background. These enhanced functions are variant-specific rather than universal features of the original framework.
AndroRAT and customized derivatives have been used by espionage actors including Bitter, Patchwork, ITG18, and SilverHawk. Bitter's early Android tooling was based on AndroRAT before evolving into BitterRAT, also known as SlideRAT. Transparent Tribe used a modified AndroRAT-derived backdoor subsequently named CapraRAT. Its use spans targeted mobile surveillance campaigns, including operations against Pakistani nationals and government personnel.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
This AndroRAT targets CVE-2015-1805, a publicly disclosed vulnerability in 2016 that allows attackers to penetrate a number of older Android devices to perform its privilege escalation. Google already patched CVE-2015-1805 in March 2016. | Trend Micro detected a new variant of Android Remote Access Tool (AndroRAT) (identified as ANDROIDOS_ANDRORAT.HRXC) that has the ability to inject root exploits to perform malicious tasks such as silent installation, shell command execution, WiFi password collection, and screen capture.
These attacks use dcRAT and QuasarRAT for Windows delivered via malicious documents exploiting CVE-2017-11882 — a memory corruption vulnerability in Microsoft Office... A typical infection would consist of a malicious document, such as an RTF file exploiting CVE-2017-11882, a stack overflow vulnerability that enables arbitrary code execution on a vulnerable version of Microsoft Office.
Bitter (aka APT-C-08 or T-APT-17) is suspected to be a South Asian hacking group motivated primarily by intelligence gathering, an operation that's facilitated by means of malware such as BitterRAT, ArtraDownloader, and AndroRAT.
Bitter (aka APT-C-08 or T-APT-17) is suspected to be a South Asian hacking group motivated primarily by intelligence gathering, an operation that's facilitated by means of malware such as BitterRAT, ArtraDownloader, and AndroRAT.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“The Bitter threat group initially started using RAT tools in their campaigns, as the first Bitter versions, for Android released in 2014 were based on the AndroRAT framework [4][5].”
Patchwork has also recently employed Android malware in its attacks, with its use of a customized version of AndroRAT.
In 2021, the group started to target the Android platform, using a modified version of an open-source RAT named AndroRAT. It bears similarities to CrimsonRAT, and has been named CapraRAT by Trend Micro in its research.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
This AndroRAT targets CVE-2015-1805... to perform its privilege escalation... The variant activates the embedded root exploit when executing privileged actions.
10 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
32 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android remote-access tool originally developed as an open-source university client/server project and later abused by cybercriminals. The described variant masquerades as TrashCleaner, exploits CVE-2015-1805 for root privileges, operates in the background, receives commands from a remote server, and steals device, communications, location, browser, Wi-Fi, and credential-related data. It can also record audio and calls, capture photos and screenshots, upload files, execute shell commands, forge or delete SMS, and silently enable accessibility services for keylogging.
Named as one of several Android malware/RAT tools the poster says they tested while seeking a working banking trojan with a control panel.
Commercial Android surveillanceware / RAT referenced as an earlier tool adopted by the actors before they developed customized tooling.
Commodity Android remote access trojan referenced as used in campaigns by Iranian APT groups.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.