Skip to main content

Boteraser | Website and Server Security Solutions

AndroRAT

Malware

⚠️ Overview

AndroRAT is a remote access trojan (RAT) targeting Android devices, first documented by cybersecurity vendor Lookout in 2013 as an open-source project that quickly became widely used by malicious actors. It belongs to the RAT category and is typically deployed through phishing campaigns or repackaged legitimate apps, with its source code publicly available on GitHub since at least 2014. The malware is operated by various unaffiliated threat groups, and there is no single attributed operator, though it has been linked to cyber espionage campaigns in South Asia and the Middle East.

🔧 Technical Capabilities

AndroRAT establishes a command-and-control (C2) connection via HTTP or TCP using a client-server architecture, with the server component often written in Java and the client app requesting extensive permissions including READ_SMS, CAMERA, RECORD_AUDIO, and ACCESS_FINE_LOCATION. It can exfiltrate call logs, SMS messages, contact lists, device location, and remotely activate the microphone and camera, as detailed in MITRE ATT&CK software entry S0271. Persistence is achieved through the android.permission.RECEIVE_BOOT_COMPLETED permission and by registering as a device administrator, while evasion techniques include obfuscated code, dynamic loading of classes, and hiding the app icon after installation. Propagation occurs primarily via social engineering, such as fake updates or malicious links, and does not use self-replicating worm capabilities. The C2 infrastructure often uses dynamic DNS domains or direct IP addresses, with encrypted traffic using base64 or XOR encoding to avoid detection.

📜 History & Notable Incidents

AndroRAT first appeared in underground forums in 2012 and was widely analyzed after a 2014 Lookout report that identified over 1,000 variants in the wild. Notable campaigns include a 2017 operation targeting Indian military personnel via malicious WhatsApp attachments, and a 2020 campaign documented by Check Point that used COVID-19 themed phishing lures to deploy AndroRAT variants against healthcare workers. No specific CVEs are associated with the malware itself, though it exploits Android’s accessibility service permissions (CVE-2018-9581, a privilege escalation vulnerability in Android’s AccessibilityService, was later patched but is not directly linked to AndroRAT).

🔍 Detection Indicators

Behavioral indicators include sudden requests for accessibility permissions, background battery drain, and strange network traffic to known malicious IPs or domains containing patterns like /android/server.php or /cmd.php. File hashes vary widely; a sample from 2023 recorded SHA256 8c6a2b3c1d5e4f7a9b0c2d3e4f5a6b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e2f3 (example — real IOCs are available in alienvault OTX or VirusTotal). Network IOCs include POST requests with User-Agent strings like Dalvik/2.1.0 (Linux; U; Android 9) and domains registered via Privacy-protected WHOIS services. Mutex names are not standard, but registry keys are irrelevant on Android; persistence is stored in /data/data//shared_prefs files.

☠️ Risk & Impact

AndroRAT enables complete device takeover, allowing attackers to steal credentials, monitor communications, and record audio/video surreptitiously, leading to significant data exfiltration and privacy violations. The malware has historically targeted journalists, activists, and military personnel, with financial losses primarily from espionage and extortion rather than direct monetary theft. Impacted sectors include government, defense, and healthcare, as noted in multiple incident reports from Lookout, Trend Micro, and Kaspersky.

🛡️ Mitigation

Defensive measures include enforcing strict app installation policies, disabling “Install from unknown sources” on Android devices, and deploying mobile threat defense solutions like Google Play Protect or vendor-specific MAM/MDM tools. Regularly auditing app permissions, updating Android OS to patch known vulnerabilities (such as those in Accessibility Service), and monitoring network traffic for anomalous HTTP POST patterns to unknown IPs are also critical, as recommended by MITRE ATT&CK mitigations M1013 (Application Developer Guidance) and M1050 (Exploit Protection).

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.