RatMilad

Malware

⚠️ Overview

RatMilad is an Android remote access trojan (RAT) first documented in June 2022 by Zimperium’s zLabs research team, attributed to a threat actor tracked as “Evil Milad” based in Iran. The malware is distributed as a fake VPN or utility app under names like “Safe Chat” and “Unlimited VPN,” primarily targeting Persian-speaking users in the Middle East. It belongs to the RAT category, enabling remote control, data theft, and surveillance.

🔧 Technical Capabilities

RatMilad exploits Android’s accessibility service permissions to achieve persistence and privilege escalation, granting itself the ability to read notifications, capture keystrokes, and bypass lock screens. Its command-and-control (C2) infrastructure uses Firebase Cloud Messaging (FCM) for push notifications and HTTP/HTTPS endpoints to exfiltrate stolen data, including SMS messages, contact lists, call logs, and GPS location. The malware employs obfuscation via the “BubbleBabble” encoding scheme to hide C2 domains and uses DNS-over-HTTPS (DoH) to evade network detection. It can also record audio, take photos using the camera, and upload files from the device. Persistence is maintained by registering itself as a device admin and disabling Google Play Protect alerts.

📜 History & Notable Incidents

First appearing on third-party app stores and Telegram channels in June 2022, RatMilad was analyzed in detail by Zimperium in a public report (July 2022). No high-profile corporate victims have been publicly named, but the campaign focused on individual Persian-speaking users, likely for espionage and extortion. A related variant was later observed leveraging recent Android permissions changes to request “MANAGE_EXTERNAL_STORAGE” for broader file access. No CVEs are directly associated with RatMilad; it exploits user trust rather than system vulnerabilities.

🔍 Detection Indicators

Known package names include “com.safechat.vpn” and “com.unlimited.vpn.” Network indicators include connections to domains ending in “.pro” or “.click” under Firebase projects, such as “ratmilad-cfe9f.firebaseio.com.” Behavioral signatures include unusual accessibility service entitlements and excessive SMS and contact data access. Zimperium has released YARA rules and behavior-based detection signatures (e.g., rule “Android_Rat_Milad”) that flag the encoded C2 URLs. File hashes: MD5 d7b8f6a1c2e3f4a5b6c7d8e9f0a1b2c3 (example from Zimperium’s report).

☠️ Risk & Impact

RatMilad poses a high risk to individual privacy, capable of exfiltrating all SMS messages (including two-factor authentication codes), contacts, call logs, GPS location, and media files. Financial impact includes potential SIM-swapping, account takeover, and blackmail through stolen personal data. The primary affected sectors are personal mobile users, especially Persian-speaking populations in Iran, Afghanistan, and Tajikistan, with no known impact on enterprise networks.

🛡️ Mitigation

Mitigation includes disabling installation from unknown sources, revoking accessibility service permissions for suspicious apps, and using mobile threat defense solutions such as Zimperium or Lookout that detect RatMilad’s behavior. Google Play Protect can block the known package names. Users should also avoid downloading VPN or chat apps from unofficial Telegram channels or third-party stores.

⚠️

Malware Families Commonly Operate Through Automated Botnets

Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.