AndroRAT is an open-source Android remote administration tool that has been repurposed as mobile malware and surveillanceware. Implemented as a client/server application with an Android client and a Java/Swing server, it is designed to run as a background service and can be configured to start at device boot. The malware provides broad remote-control and collection capabilities on Android devices, including theft of SMS messages, call logs, and contact data; collection of device location via GPS or network sources; microphone audio capture; real-time monitoring of messages and phone-state events; camera use; sending SMS messages; placing phone calls; opening URLs; and other device-control actions.
Because it is openly available and relatively accessible, AndroRAT has appeared both as a commodity Android RAT and as a building block for customized mobile espionage tooling. Multiple threat actors have used or adapted it, including Bitter and Patchwork, and reporting has also linked its historical use to Iranian-aligned ITG18 activity. Transparent Tribe later used a modified variant derived from AndroRAT that became known as CapraRAT. Operational use has included espionage-oriented campaigns in South Asia, with lures and trojanized Android applications tailored to regional political, religious, and social themes.
AndroRAT is associated with Android surveillance operations focused on intelligence collection from mobile devices rather than destructive effects. Its functionality supports persistent access, post-compromise monitoring, and exfiltration of sensitive user communications and contextual device data.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
These attacks use dcRAT and QuasarRAT for Windows delivered via malicious documents exploiting CVE-2017-11882 — a memory corruption vulnerability in Microsoft Office... A typical infection would consist of a malicious document, such as an RTF file exploiting CVE-2017-11882, a stack overflow vulnerability that enables arbitrary code execution on a vulnerable version of Microsoft Office.
Bitter (aka APT-C-08 or T-APT-17) is suspected to be a South Asian hacking group motivated primarily by intelligence gathering, an operation that's facilitated by means of malware such as BitterRAT, ArtraDownloader, and AndroRAT.
Bitter (aka APT-C-08 or T-APT-17) is suspected to be a South Asian hacking group motivated primarily by intelligence gathering, an operation that's facilitated by means of malware such as BitterRAT, ArtraDownloader, and AndroRAT.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Bitter (aka APT-C-08 or T-APT-17) is suspected to be a South Asian hacking group motivated primarily by intelligence gathering, an operation that's facilitated by means of malware such as BitterRAT, ArtraDownloader, and AndroRAT.
Patchwork has also recently employed Android malware in its attacks, with its use of a customized version of AndroRAT.
In 2021, the group started to target the Android platform, using a modified version of an open-source RAT named AndroRAT. It bears similarities to CrimsonRAT, and has been named CapraRAT by Trend Micro in its research.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
Cisco Talos attributed the activity with moderate confidence to a hacking group dubbed the Bitter APT based on overlaps in the command-and-control (C2) infrastructure with that of prior campaigns mounted by the same actor.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
29 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Commercial Android surveillanceware / RAT referenced as an earlier tool adopted by the actors before they developed customized tooling.
Commodity Android remote access trojan referenced as used in campaigns by Iranian APT groups.
Android remote access trojan referenced as possible source-code inspiration for CapraRAT; documentation notes instability after Android version 9.
Open-source Android RAT referenced as the basis for the modified malware later named CapraRAT.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.