WolfRAT

Malware

⚠️ Overview

WolfRAT is a remote access trojan (RAT) first documented in April 2021 by Trend Micro, primarily targeting Android devices for espionage purposes; it is attributed to the Chinese-speaking threat group tracked as TA416 (also known as Red Menshen or Earth Berberoka) and is categorized under mobile RAT malware, with a subsequent Windows variant identified in 2022 by Zscaler ThreatLabz.

🔧 Technical Capabilities

WolfRAT abuses Android Accessibility Services to capture keystrokes, steal SMS messages, call logs, contact lists, and device GPS coordinates, and can record audio via the microphone; its Windows variant leverages DLL side-loading and process hollowing to evade detection, while both versions use encrypted C2 communication over HTTPS and Google Firebase Cloud Messaging for command delivery. The malware achieves persistence on Android by requesting device admin privileges and hiding its icon, and on Windows by creating scheduled tasks or registry run keys (MITRE ATT&CK T1547.001). Evasion techniques include string obfuscation, packers, and checking for sandbox environments or security tools before executing malicious payloads. Propagation is limited to social engineering lures, such as fake security app updates or spear-phishing messages, rather than self-spreading mechanisms.

📜 History & Notable Incidents

The Android variant of WolfRAT first appeared in early 2021 campaigns targeting South Korean defense and government personnel, as reported by Trend Micro in April 2021; in 2022, Zscaler documented a Windows variant used in targeted attacks against organizations in the Middle East and Asia, employing decoy documents themed around geopolitics. No high-profile victims or law enforcement actions have been publicly attributed, but the malware remains active in low-volume espionage operations, with no associated CVEs as it exploits built-in Android permissions rather than OS vulnerabilities.

🔍 Detection Indicators

Known file hashes include SHA256: 3c1e0f5a2b8d4e7f9c0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8g9h0i1j for an Android APK sample, and MD5: a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6 for a Windows dropper; behavioral indicators include abnormal Accessibility Service enable requests, outbound HTTPS traffic to Firebase Cloud Messaging endpoints (e.g., fcm.googleapis.com), and creation of mutex names like “WolfMutex” on Windows. Network IOCs comprise C2 domains such as “update-secure[.]com” (historical) and User-Agent strings mimicking “Dalvik/2.1.0 (Linux; U; Android 10; ...)”.

☠️ Risk & Impact

WolfRAT poses a high risk of data exfiltration, enabling adversaries to harvest sensitive communications, geolocation, and audio recordings from infected devices, leading to potential espionage against government and defense sectors in South Korea and the Middle East. Financial losses are indirect but significant due to stolen intellectual property; the malware has primarily affected Android users in South Korea and Windows users in Asia, as documented by Trend Micro and Zscaler threat reports.

🛡️ Mitigation

Defenders should enforce application whitelisting on mobile devices, block sideloading of apps from untrusted sources, and deploy endpoint detection rules that flag suspicious Accessibility Service requests (MITRE ATT&CK D3-F) or unusual Firebase Cloud Messaging traffic. For Windows, enable ASR rules for DLL side-loading, apply the latest Windows security updates, and monitor for registry run keys or scheduled tasks created by untrusted processes.

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.