AndroRat
Malware family · 4 sample(s) · 4 indicator record(s) · 2 signing certificate(s)
About AndroRat
One of the oldest open-source Android RATs (first released ~2012), still repackaged into fresh campaigns. Classic builds carry the my.app.client package; repackaged flavors ship under innocuous package names and app titles like "Google Service Framework".
Indicators
| Indicator | Type | Sample | First seen |
|---|---|---|---|
| 192.169.x.x:8000 | domain | c5ab0adaedf3… | 2025-12-29 |
| hacker12345.ddns.net:100 | domain | 18f02dd87210… | 2019-10-08 |
| jonnyro.ddns.net:1604 | domain | 28f8b2b56852… | 2019-10-04 |
| 3.67.78.149:2002 | ip | 347f1b018f64… | 2023-05-10 |