Skip to content
 
 

Latest commit

 

History

9 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 

Repository files navigation

RAT-DIR-logo.png

Android Remote Access Trojan (RAT) Directory

This repository serves as a comprehensive documentation directory of known Android Remote Access Trojans (RATs), compiling free, commercial, open-source, and leaked variants alongside their core tracking payloads, features, and systemic permission requirements.

Important

Educational & Research Purpose Only: This information is intended strictly for security researchers, malware analysts, and educational documentation.


⚠️ Security Warning

Caution

HIGH INFECTION RISK: DO NOT download, compile, or execute these projects unless you fully understand the systemic risks involved.

  • There is an exceptionally high risk of being infected by the tools/builders themselves.
  • Always leverage isolated sandboxes (VMs/Emulators) and thoroughly inspect all source code or executables.
  • Remember: A Trojan hidden inside a Trojan builder is a highly common delivery vector.

☠️ Vx-Underground

Additional archived references and general trojan documentation can be found here:

🛠️ Utility & External Archives

  • Dataset Archive: Access the broader telemetry dataset via the Android RAT Dataset.
  • Network Testing: If you require port forwarding without purchasing a VPN or modifying local router rules, utilize Ngrok.

🏆 Top 10 RATs List

The following ranking lists the Top 10 Android Remote Access Trojans documented in this directory, ordered by their total number of verified functional features & remote capabilities.

1. Lab-RATS 🧪 (Free/Open Source)

Score: 15/21 Checkmarks

Known Link: https://github.com/K4N3CO/Lab-RATS

  • Verified Matrix Checks: GUI(PC/Mobile), Camera, Mic, SMS, MMS, Contact, Call, Call Logs, Storage, Location, Screenshot, Notification, Keylogger, Remote Takeover, Stealth Mode, and more.
  • Infrastructure Edge: Bypasses classic port-forwarding constraints entirely by utilizing native IPv6 direct traversal pipelines. Optimized to support modern target testing layouts all the way up to Android SDK 36 (OneUI 8.5+).

2. SpyNote 👁️ (Paid Commercial Origin)

Score: 12/21 Checkmarks

  • Verified Matrix Checks: GUI, Camera, Mic, SMS, Contact, Call, Call Logs, Storage, Location, Browser, App List, Notification.
  • Infrastructure Edge: Heavily optimized for system-wide sensory dominance. It handles direct payload app-binding, extracts environmental audio loops, and traces hidden hardware telemetry (IMEI/WIFI MAC).

3. Hawkshaw 🦅 (Free)

Score: 11/21 Checkmarks

Known Link: https://github.com/saksham2410/Android-RAT---Hawkshaw

  • Verified Matrix Checks: Camera, Mic, SMS, Contact, Call, Storage, Location, Account Detail, Lock/Vibrate/Flash, App Management, Keylogger.
  • Infrastructure Edge: Optimizes persistent data pipelines and social log exfiltration points, ensuring high tracking density directly following reboot sequences.

4. LokiDroid ⚡ (Free)

Score: 10/21 Checkmarks

  • Verified Matrix Checks: GUI, Camera, Mic, SMS, Contact, Call, Call Logs, Storage, Location, Browser.
  • Infrastructure Edge: Designed as a multi-bot HTTP client that removes port-forwarding constraints through an asynchronous web C2 control platform.

5. Cerberus Banking 🐕 (Commercial Leased Botnet)

Score: 10/21 Checkmarks

  • Verified Matrix Checks: GUI, Mic, SMS, Contact, Storage, Location, App List, Admin Control, Inject, Phishing.
  • Infrastructure Edge: A highly destructive financial botnet engine designed for systemic mobile banking takeover. It uses a specialized commercial control panel to coordinate real-time overlay delivery across thousands of distributed zombie targets.

6. AIRAVAT 🦅 (Free)

Score: 10/21 Checkmarks

  • Verified Matrix Checks: Camera, Mic, SMS, Contact, Call, Call Logs, Storage, App List, Screenshot, Shell.
  • Infrastructure Edge: A dual-threat exploitation framework merging continuous surveillance loops with an automated system-locking Ransomware module.

7. DroidJack 🔌 (Free)

Score: 10/21 Checkmarks

  • Verified Matrix Checks: GUI, Camera, Mic, SMS, Contact, Call, Storage, Location, Browser, App List.
  • Infrastructure Edge: The historical reference baseline for Android monitoring tools. Maps complete local directories and captures intact WhatsApp messaging databases.

8. Android Spyware 🕵️ (Free)

Score: 9/21 Checkmarks

Known Link: https://github.com/CanciuCostin/android-spyware

  • Verified Matrix Checks: SMS, Call, Contact, Device Info, App List (Install Apps), App List (Get Apps), WebView Inject, Camera, Storage, Mic, ADB Command Control.
  • Infrastructure Edge: Offers a dense, raw framework that focuses heavily on sensory extraction and deep background system control via automated low-level ADB shell injection.

9. Nexus 🔗 (Free)

Score: 9/21 Checkmarks

  • Verified Matrix Checks: Camera, Mic, SMS, Call, Storage, Location, Keylogger, Shell, Inject.
  • Infrastructure Edge: A sophisticated threat focused on financial target exploitation, automating crypto-wallet hijacking, web overlay phishing injection, and 2FA authenticator database harvesting.

10. AhMyth 🛠️ (Free)

Score: 9/21 Checkmarks

Known Link: https://github.com/AhMyth/AhMyth-Android-RAT

  • Verified Matrix Checks: GUI, Camera, Mic, SMS, Contact, Call, Call Logs, Storage, Location.
  • Infrastructure Edge: A lightweight open-source framework frequently used as an analytical baseline for background media exfiltration and continuous GPS polling loops.

📊 Comprehensive RAT Features Data Table (A-Z)

Name GUI OS Camera Mic SMS MMS Contacts Call Call Logs Storage Location Browser App List Admin Control Keylogger Screenshot Shell Notification Remote Takeover Inject Phishing Stealth Mode GitHub Link Special Feature
Adobot ❌ 🐧💻 ❌ ❌ ✔️ ❌ ✔️ ✔️ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ✔️ ❌ ❌ ❌ ❌ ✔️ ✔️ https://github.com/adonespitogo/AdoBot Realtime command execution, Schedule commands
AhMyth ✔️ 🐧💻 ✔️ ✔️ ✔️ ❌ ✔️ ✔️ ✔️ ✔️ ✔️ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ https://github.com/AhMyth/AhMyth-Android-RAT -
AIRAVAT ❌ 🐧💻 ✔️ ✔️ ✔️ ❌ ✔️ ✔️ ✔️ ❌ ❌ ✔️ ✔️ ❌ ✔️ ✔️ ❌ ❌ ❌ ❌ ❌ ❌ https://github.com/Th30neAnd0nly/AIRAVAT
https://github.com/GoutamHX/MAXXRAT
Ransomware, Shell Command
Android Spy App ❌ 🐧💻 ❌ ❌ ✔️ ❌ ✔️ ✔️ ✔️ ✔️ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ https://github.com/abhinavsuthar/Android_Spy_App Logs
Android Spyware ❌ 🐧💻 ✔️ ✔️ ✔️ ❌ ✔️ ✔️ ✔️ ❌ ❌ ✔️ ❌ ❌ ❌ ✔️ ❌ ❌ ❌ ❌ ❌ ❌ https://github.com/CanciuCostin/android-spyware Adb command control
android_trojan ❌ 🐧💻 ❌ ✔️ ✔️ ❌ ✔️ ✔️ ✔️ ✔️ ✔️ ✔️ ❌ ❌ ❌ ✔️ ❌ ❌ ❌ ❌ ❌ ❌ https://github.com/androidtrojan1/android_trojan Browser history, Add/remove app
Android Voyage ❌ 🐧💻 ❌ ❌ ✔️ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ✔️ ✔️ ❌ ❌ ❌ ❌ ❌ ❌ ✔️ - Remote Screen, Traffic monitor, System app, Lock/unlock, Hide app, Remove password, Brick device, Anti Antivirus, Self Destructive, Password Grabbers
AndroRAT ✔️ 🐧💻 ✔️ ✔️ ✔️ ❌ ✔️ ✔️ ❌ ✔️ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ https://github.com/DesignativeDave/androrat
https://github.com/karma9874/AndroRAT
https://github.com/The404Hacking/AndroRAT
Streaming Video, Toast, Vibrate, Open URL
AndroSpy ❌ 🐧💻 ✔️ ❌ ✔️ ❌ ✔️ ❌ ✔️ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ https://github.com/qH0sT/AndroSpy Install, Inject
Arsink RAT ❌ 🐧💻 ❌ ❌ ✔️ ❌ ✔️ ❌ ❌ ✔️ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ✔️ ❌ ❌ - Sniff, Phishing
BetterAndroRAT ❌ 🐧💻 ✔️ ✔️ ✔️ ❌ ✔️ ✔️ ✔️ ✔️ ❌ ✔️ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ https://github.com/mwsrc/BetterAndroRAT Add/remove app, Remote Device Controller
Name GUI OS Camera Mic SMS MMS Contacts Call Call Logs Storage Location Browser App List Admin Control Keylogger Screenshot Shell Notification Remote Takeover Inject Phishing Stealth Mode GitHub Link Special Feature
BlueEagle jRAT ❌ 🐧💻 ✔️ ✔️ ✔️ ❌ ✔️ ❌ ✔️ ✔️ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ - Phone Information, Account Detail, Owner Access (Boot), Block google protect
BRAT ❌ 🐧💻 ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ✔️ ✔️ ❌ ❌ ❌ ❌ ❌ ✔️ ❌ ❌ ❌ - Install and remove apps, Factory Reset
Casperspy ✔️ 🐧💻 ✔️ ✔️ ✔️ ❌ ❌ ❌ ✔️ ❌ ✔️ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ https://github.com/dhanumurti Botnet by dendroid, Browser open page
Cerberus App ❌ 🐧💻 ✔️ ❌ ❌ ❌ ❌ ❌ ✔️ ✔️ ❌ ❌ ✔️ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ - Not deletable
Cerberus Bank ✔️ 🐧💻 ❌ ✔️ ✔️ ❌ ✔️ ❌ ❌ ✔️ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ - Bank and CC Logs, Mail logs, Turnoff Play Protected, Download/Install/Remove Apps, Lock device
Chameleon ❌ 🐧💻 ❌ ❌ ✔️ ❌ ✔️ ❌ ✔️ ❌ ❌ ❌ ❌ ✔️ ✔️ ❌ ❌ ❌ ❌ ✔️ ❌ ❌ - Screen Capture, Overlay, Proxy, Cookies Stealer
columbus-trojan ❌ 🐧💻 ✔️ ✔️ ❌ ❌ ❌ ❌ ❌ ✔️ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ https://github.com/project-columbus/trojan Front-facing camera, 10s sound clip, Mobile triangulation
Darkweb PexRat ❌ 🐧💻 ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ✔️ ❌ ✔️ ❌ ❌ ❌ ❌ ❌ ❌ ❌ - Screen, Infostealer
Dash ✔️ 🐧💻 ✔️ ❌ ✔️ ❌ ✔️ ✔️ ❌ ✔️ ❌ ❌ ❌ ❌ ✔️ ❌ ❌ ✔️ ❌ ❌ ✔️ ✔️ https://github.com/muneebwanee/Dash Multiple Child clients, Environment recording, Notifications received
Dendroid ❌ 🐧💻 ✔️ ❌ ✔️ ❌ ✔️ ✔️ ❌ ❌ ✔️ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ https://github.com/nyx0/Dendroid Opening web pages, Uploading images/video, Denial-of-service, Change C&C server
DogeRAT ❌ 🐧💻 ✔️ ❌ ✔️ ❌ ❌ ❌ ❌ ❌ ❌ ✔️ ✔️ ✔️ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ - Install/remove apps, GetApps, Inject
Name GUI OS Camera Mic SMS MMS Contacts Call Call Logs Storage Location Browser App List Admin Control Keylogger Screenshot Shell Notification Remote Takeover Inject Phishing Stealth Mode GitHub Link Special Feature
DroidJack ✔️ 🐧💻 ✔️ ✔️ ✔️ ❌ ✔️ ❌ ✔️ ✔️ ✔️ ✔️ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ - Whatsapp Reader, Browser History, App Manager
ERMAC ❌ 🐧💻 ❌ ❌ ✔️ ❌ ✔️ ❌ ❌ ❌ ❌ ✔️ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ - InstallApps, GetApps
Fantasy Hub ❌ 🐧💻 ✔️ ✔️ ✔️ ❌ ✔️ ❌ ✔️ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ - 2FA, Realtime Cam/Mic, Permission runtime
FinSpy ❌ 🐧💻 ❌ ✔️ ✔️ ❌ ✔️ ❌ ✔️ ✔️ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ - Phone information, Mms, Voip record (Skype, WeChat, Viber, LINE)
GhostCtrl ❌ 🐧💻 ❌ ✔️ ✔️ ❌ ❌ ❌ ❌ ✔️ ❌ ❌ ✔️ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ - Voice record
Gigabud RAT ❌ 🐧💻 ❌ ❌ ❌ ❌ ❌ ❌ ✔️ ❌ ❌ ❌ ❌ ✔️ ✔️ ❌ ❌ ❌ ❌ ❌ ❌ ❌ - Screen record, Install package
GoldDigger ❌ 🐧💻 ❌ ❌ ✔️ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ✔️ ✔️ ❌ ❌ ❌ ❌ ✔️ ❌ ❌ - -
GravityRAT ❌ 🐧💻 ❌ ❌ ✔️ ❌ ✔️ ❌ ✔️ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ - Exfiltrate data
HaxRAT ❌ 🐧💻 ✔️ ✔️ ❌ ❌ ❌ ❌ ✔️ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ https://github.com/Hax4us/haxRat Audio recording
Hawkshaw ❌ 🐧💻 ✔️ ✔️ ✔️ ❌ ✔️ ❌ ✔️ ✔️ ❌ ❌ ❌ ✔️ ❌ ❌ ❌ ❌ ❌ ❌ ✔️ ❌ https://github.com/saksham2410/Android-RAT---Hawkshaw Account Detail, Lock, Vibrate, Flash, Owner Access (Boot), Inject, Logs/Keylog (messenger, socialmedia)
Name GUI OS Camera Mic SMS MMS Contacts Call Call Logs Storage Location Browser App List Admin Control Keylogger Screenshot Shell Notification Remote Takeover Inject Phishing Stealth Mode GitHub Link Special Feature
Hector / ISOON ❌ 🐧💻 ❌ ❌ ✔️ ❌ ✔️ ❌ ✔️ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ - Log system multi platform, adb control
Hidden Cobra ❌ 🐧💻 ❌ ❌ ✔️ ❌ ✔️ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ - Proxy, Payload
HighRise ❌ 🐧💻 ❌ ❌ ✔️ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ - Incoming/outgoing SMS
IMG-RAT ❌ 🐧💻 ✔️ ✔️ ✔️ ❌ ✔️ ❌ ✔️ ❌ ❌ ❌ ❌ ✔️ ❌ ✔️ ❌ ❌ ❌ ❌ ❌ ❌ - Shell integration
i-spy Android ❌ 🐧💻 ✔️ ❌ ❌ ❌ ❌ ❌ ✔️ ✔️ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ https://github.com/JohnReagan/i-spy-android Standard filesystem storage
Joanap ❌ 🐧💻 ❌ ✔️ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ - Botnet, Steal log
Joker ❌ 🐧💻 ❌ ❌ ✔️ ❌ ✔️ ❌ ✔️ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ - Manipulating subscription (money), Play Store infection
KevDroid ❌ 🐧💻 ❌ ✔️ ✔️ ❌ ✔️ ✔️ ✔️ ✔️ ❌ ✔️ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ - Installed apps, Phone number, Unique ID, Mails
Lab-RATS ✔️ 🐧💻🍎 ✔️ ✔️ ✔️ ✔️ ✔️ ✔️ ✔️ ✔️ ✔️ ❌ ❌ ❌ ✔️ ✔️ ❌ ✔️ ✔️ ❌ ❌ ✔️ https://github.com/K4N3CO/Lab-RATS IPv6 traversal, Works on Newest Android(SDK 36), Blackout Mode(screen blinding), Remote App Restart(SMS Prompt), Anti-Removal Sheild, Ghost Mechanics, Self Healing, Functional App Decoys.
LaRAT ❌ 🐧💻 ✔️ ❌ ✔️ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ✔️ ❌ ❌ ❌ ❌ ✔️ ❌ ❌ https://github.com/c4wrd/LaRat Add Google form for passwords
LodaRAT ❌ 🐧💻 ✔️ ✔️ ❌ ❌ ✔️ ❌ ✔️ ✔️ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ - Install application, Account Credentials
Name GUI OS Camera Mic SMS MMS Contacts Call Call Logs Storage Location Browser App List Admin Control Keylogger Screenshot Shell Notification Remote Takeover Inject Phishing Stealth Mode GitHub Link Special Feature
LokiDroid ✔️ 🐧💻 ✔️ ✔️ ✔️ ❌ ✔️ ✔️ ✔️ ✔️ ✔️ ✔️ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ - Phone details, Sim/Internet details, Offline commands, Multiple bots, http RAT
Mass RAT ❌ 🐧💻 ✔️ ❌ ✔️ ❌ ✔️ ❌ ✔️ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ https://github.com/NYAN-x-CAT/Mass-RAT -
MMRat ❌ 🐧💻 ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ✔️ ✔️ ✔️ ❌ ❌ ❌ ❌ ❌ ❌ - adb command automation
Monokle ❌ 🐧💻 ❌ ✔️ ✔️ ❌ ✔️ ✔️ ❌ ✔️ ✔️ ❌ ❌ ✔️ ✔️ ✔️ ❌ ❌ ❌ ❌ ❌ ❌ - Screen recording, Fingerprint-device duplicate, Shell as root
NetWire ✔️ 🐧💻 ✔️ ✔️ ❌ ❌ ❌ ❌ ✔️ ✔️ ❌ ❌ ❌ ✔️ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ - Download/Upload pipelines
Nexus ❌ 🐧💻 ✔️ ✔️ ✔️ ❌ ✔️ ❌ ✔️ ✔️ ❌ ❌ ❌ ✔️ ❌ ✔️ ❌ ❌ ❌ ✔️ ❌ ❌ - Inject Banking, Crypto app, 2FA app database
Nivistealer ❌ 🐧💻 ✔️ ❌ ❌ ❌ ❌ ❌ ❌ ✔️ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ✔️ ❌ ❌ https://github.com/swagkarna/Nivistealer IP, Web steal based, set phishing site
OmniRAT ✔️ 🐧💻 ❌ ❌ ✔️ ❌ ✔️ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ✔️ ❌ ❌ ❌ ❌ ❌ ❌ - Full Remote Access, File Manager, App Widgets, Full System Information
Pegasus ❌ 🐧💻🍎 ❌ ✔️ ✔️ ❌ ✔️ ✔️ ✔️ ✔️ ✔️ ❌ ❌ ❌ ✔️ ❌ ❌ ❌ ❌ ❌ ❌ ❌ https://github.com/9aylas/Pegasus-samples
https://github.com/jonathandata1/pegasus_spyware
Calendar, Instant Messaging, Mail, Device Setting
PounceKeys ❌ 🐧💻 ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ✔️ ❌ ❌ ✔️ ❌ ❌ ❌ ✔️ ❌ https://github.com/NullPounce/pounce-keys Phone info extraction, clipboard memory scraping
Pupy ❌ 🐧💻 ✔️ ❌ ❌ ❌ ❌ ❌ ❌ ✔️ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ https://github.com/n1nj4sec/pupy Text to speech, Webcam snapshots (front & back)
Name GUI OS Camera Mic SMS MMS Contacts Call Call Logs Storage Location Browser App List Admin Control Keylogger Screenshot Shell Notification Remote Takeover Inject Phishing Stealth Mode GitHub Link Special Feature
Rafel RAT ❌ 🐧💻 ✔️ ✔️ ❌ ❌ ✔️ ✔️ ✔️ ✔️ ✔️ ❌ ✔️ ❌ ❌ ❌ ✔️ ❌ ❌ ❌ ❌ ❌ github.com/swagkarna/Rafel-Rat Ransomware module, Persistence mechanisms
rdroid ❌ 🐧💻 ❌ ❌ ✔️ ❌ ✔️ ❌ ✔️ ❌ ❌ ✔️ ❌ ❌ ❌ ✔️ ❌ ❌ ❌ ❌ ❌ ❌ github.com System diagnostics
Rogue RAT ❌ 🐧💻 ✔️ ✔️ ❌ ❌ ❌ ❌ ✔️ ✔️ ❌ ❌ ❌ ✔️ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ - Continuous telemetry
SHConnect ❌ 🐧💻 ✔️ ❌ ❌ ❌ ❌ ❌ ✔️ ✔️ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ - Basic tracking
SpyApp Client ✔️ 🐧💻 ❌ ❌ ✔️ ❌ ✔️ ✔️ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ✔️ ❌ ❌ ❌ ❌ ❌ github.com/ghazikr/SpyAppClient Notification Listener (Facebook, whatsapp, instagram etc)
SpyNote ✔️ 🐧💻 ✔️ ✔️ ✔️ ❌ ✔️ ✔️ ✔️ ✔️ ✔️ ✔️ ✔️ ✔️ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ - Bind app, Live mic streaming/recording, Hardware details, Fun Panel
Steaelite RAT ❌ 🐧💻 ❌ ❌ ❌ ❌ ❌ ❌ ✔️ ❌ ❌ ❌ ❌ ✔️ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ - Ransomware
Strandhogg ❌ 🐧💻 ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ - Hijack Session, apps log, wide permission injection
StrongPity ❌ 🐧💻 ❌ ❌ ❌ ❌ ✔️ ❌ ✔️ ✔️ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ - Boot, Network Info tracking
TalentRAT ❌ 🐧💻 ✔️ ✔️ ✔️ ❌ ✔️ ❌ ❌ ✔️ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ github.com/honglvt/TalentRAT -
TearDroid PHP ❌ 🐧💻 ❌ ❌ ✔️ ❌ ✔️ ✔️ ❌ ✔️ ❌ ✔️ ❌ ❌ ❌ ✔️ ❌ ❌ ❌ ❌ ❌ ❌ github.com/ScRiPt1337/Teardroid-phprat Running Services tracker, findphno/findx:pdf command integration, Change Wallpaper
TecSpy ❌ 🐧💻 ❌ ❌ ✔️ ❌ ✔️ ❌ ✔️ ✔️ ❌ ❌ ✔️ ❌ ❌ ✔️ ✔️ ✔️ ❌ ❌ ❌ ❌ github.com Notification logger, Admin adb operations
Name GUI OS Camera Mic SMS MMS Contacts Call Call Logs Storage Location Browser App List Admin Control Keylogger Screenshot Shell Notification Remote Takeover Inject Phishing Stealth Mode GitHub Link Special Feature
TeleRAT/IIRAT ❌ 🐧💻 ✔️ ✔️ ✔️ ❌ ✔️ ❌ ✔️ ❌ ❌ ✔️ ✔️ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ - Telegram BOT integration, Control Admin Screen, Vibrate
TheFatRAT ❌ 🐧💻🍎 ✔️ ✔️ ❌ ❌ ❌ ❌ ✔️ ❌ ❌ ❌ ❌ ❌ ❌ ✔️ ❌ ❌ ❌ ❌ ❌ ❌ github.com/Screetsec/TheFatRat Execute command, process list optimization
Triout Framework ❌ 🐧💻 ✔️ ❌ ✔️ ❌ ❌ ✔️ ✔️ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ✔️ ✔️ - Record phonecall, Steal images/video, Hide app icon
UnknownRAT ✔️ 🐧💻 ✔️ ✔️ ❌ ❌ ❌ ❌ ✔️ ❌ ❌ ❌ ❌ ❌ ✔️ ❌ ❌ ❌ ❌ ❌ ❌ ❌ - Android Tools (photo, screenshot), Record audio
WH-RAT ✔️ 🐧💻 ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ github.com Similar with SpyNote NjRAT
Xenomorph / GODFather / PixPirate / Sova / Zanubis / BingoMod / TrickMo / BlankBot / Vultur / Octo2 / Medusa ❌ 🐧💻 ✔️ ❌ ✔️ ❌ ❌ ❌ ✔️ ❌ ❌ ✔️ ✔️ ❌ ❌ ✔️ ✔️ ❌ ❌ ✔️ ❌ ❌ - Fully Control Device, Overlay systems, Bypasses standard biometric/PIN locks
ZeroDayRAT ❌ 🐧💻 ✔️ ✔️ ✔️ ❌ ✔️ ❌ ❌ ❌ ❌ ❌ ❌ ✔️ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ - Cryptostealer, Device info profiles

📊 Comprehensive RAT Matrix (A-Z)

Trojan Name UI / Interface Type Project Links / Repositories Core Features & Permissions
Adobot CLI Tracker • adonespitogo/AdoBot Real-time command loop execution, Cron/Scheduled commands, Icon concealment (Stealth mode), Contacts/SMS/Call logs extraction.
AhMyth GUI • AhMyth/AhMyth-Android-RAT Camera, Microphone, Storage, GPS tracker, SMS interception, Call log extraction, Contacts dumping.
AIRAVAT CLI / Payload • Th30neAnd0nly/AIRAVAT
• GoutamHX/MAXXRAT
Direct filesystem storage parsing, Device Administrator permission hooks, App listing vectors, Complete communication mining (SMS/Call/Contacts), Front/Back camera capture, Ambient microphone scraping, Remote screen capture pipelines, System-locking Ransomware payload, Interactive remote shell environment.
Android Spy App CLI • abhinavsuthar/Android_Spy_App Contacts/Call logs/SMS data mining, General diagnostic logs, GPS tracker, External storage access.
Android Spyware Comprehensive Framework • CanciuCostin/android-spyware Complete communication logging (SMS/Call/Contacts), System information mapping, App package indexing/installation, WebView credential injection, Camera capture, Local storage parsing, Microphone capture, Arbitrary ADB shell command execution.
Android Trojan CLI • androidtrojan1/android_trojan Interactive shell, Browser history, Microphone, GPS tracking, Storage, App management, Contacts/SMS/Call log dumping.
Android Voyage CLI N/A Remote screen mirroring, Screenshots, Keylogging, Traffic monitoring, Persistent system app conversion, Passcode removal, Anti-Antivirus mechanics, Self-destructive mode, Credential grabbers.
AndroRAT GUI Available • DesignativeDave/androrat
• karma9874/AndroRAT
• The404Hacking/AndroRAT
Contacts, Call logs, SMS, GPS, Camera, Mic, Live video streaming, UI Toast messages, URL redirection, Device vibration.
AndroSpy CLI • qH0sT/AndroSpy Camera triggers, SMS monitoring, Contact extraction, Call history harvesting, Local storage read/write access, Arbitrary package installation and code injection.
Arsink RAT Spyware Vector N/A Complete text parsing (SMS channels), Contact data scraping, Voice call logging pipelines, GPS path mapping, Local network traffic sniffing, Custom social application overlay phishing.
BetterAndroRAT CLI • mwsrc/BetterAndroRAT Package installation/removal, Camera, Microphone, Storage access, Call & SMS routing, Remote hardware controller.
BlueEagle jRAT Desktop Client Link N/A Call/SMS/Contact monitoring, Core system data mining, Camera frame capture, Ambient audio capture, Real-time location parsing, Target account info tracking, Boot persistence hooks, Google Play Protect disabling functions.
BRAT Brazilian Banking RAT N/A Silently installs/uninstalls application layers, Package enumeration, Credential injection modules, Force factory reset execution, Device Administrator privilege hijacking.
Casperspy GUI Botnet • dhanumurti Dendroid-derived botnet architecture, SMS logging, Camera/Storage/Microphone tracking, Remote browser manipulation.
Cerberus App Admin Client N/A Storage access, Real-time GPS location, Camera triggers, Admin privilege persistence, Anti-uninstallation hooks.
Cerberus Banking GUI Panel N/A Botnet overlay mechanics, Core banking/Credit Card credential logging, Mail database harvesting, Call forwarding injection, Audio/SMS/GPS trackers, Play Protect security disabling, Remote application installer/remover, Hard screen lock.
Chameleon Advanced Stealer N/A Target layout phishing templates, Automated system keylogger engine, Contact/SMS/Call tracking databases, Local data storage mining, Live layout screen capture, Dynamic input field accessibility overlays, Local SOCKS proxy establishment, Browser session cookie stealing.
Columbus-Trojan CLI • project-columbus/trojan Minimalist stealth design: Front-facing camera snap, 10-second mic audio clipping, Triangulated cell network location.
Darkweb PexRat Commercial Spyware N/A Continuous screen capturing/mirroring framework, Device Administrator validation enforcement, Distributed infostealer profile modules.
Dash GUI Control Panel • muneebwanee/Dash Integrated camera control, Multi-child client control array, Dynamic launcher icon hiding (Stealth mode), Live GPS coordinates mapping, Bi-directional call recording (Incoming/Outgoing), SMS transaction indexing, Ambient audio monitoring, Native keylogger engine, Targeted social network web phishing templates, Notification stream listeners (WhatsApp, Instagram, Messenger).
Dendroid Panel Control • nyx0/Dendroid Full SMS/Call monitoring, Forced HTTP page opening, Remote video/image exfiltration, App initialization, Native DDoS execution panels, Dynamic C2 reassignment.
DogeRAT Admin Panel Client N/A Stealth app package installation/uninstallation, Active package enumeration, Over-the-air injection layers, Real-time camera frames capture, SMS network monitoring, Integrated device keylogging, Full Device Administrator control.
DroidJack GUI N/A (Closed/Leaked) Camera, Mic, GPS, Storage, SMS/Calls/Contacts, WhatsApp reader, Browser history, App manager.
ERMAC Banking Botnet N/A Automated SMS/Call log interception, Contact database exfiltration, Installed application scanning, Package execution commands, Automated WebView overlay injection.
Fantasy Hub Surveillance Toolkit N/A Direct text tracing (SMS pipelines), 2FA validation token interception, Target contact tracking, Real-time video/microphone parsing, Local directory data traversal, Runtime prompt permission interaction hijacking.
FinSpy Commercial Spyware N/A Advanced storage harvesting, System metadata collection, Call/SMS/MMS extraction, GPS tracking, Native VoIP stream recording (Skype, WeChat, Viber, LINE).
GhostCtrl Admin Client N/A Device administrator privilege escalation, Persistent voice recording, SMS routing, GPS location caching.
Gigabud RAT Screen Stealer N/A Real-time screen recording/mirroring pipelines, Storage file extraction, Package deployment/installation hooks, Custom localized keylogging engines.
GoldDigger Financial Malware N/A Native accessibility-driven keylogger engine, Screen layout scraping, Transaction text SMS interception, Target banking web overlay phishing templates.
GravityRAT Targeted Spyware N/A Background SMS mining, Contact exfiltration, Call log interceptor, Mass system folder exfiltration routines.
HaxRAT Framework / Payload • Hax4us/haxRat Complete external/internal storage traversal, Direct camera control, Live room microphone capture.
Hawkshaw CLI / Framework • saksham2410/Android-RAT---Hawkshaw Full communication log harvesting, Audio/Video/GPS capture, Device user account details theft, Hardware manipulation (Lock, vibrate, flash), Boot-persistence execution hook, Stealth app management, Messenger keylogging overlays.
Hector / ISOON RAT APT / Multiplatform N/A Local filesystem mapping, SMS communication streams extraction, Contact logs lifting, Multi-platform unified system log engine, Low-level administrative ADB control modules.
Hidden Cobra APT Payload N/A Network proxy hosting, Contact database lifting, SMS exploitation, Secondary malicious payload drop vectors.
HighRise Background Service N/A Proxy-based capture of incoming and outgoing SMS traffic.
IMG-RAT Payload Generator N/A Local directory storage traversal, Camera state triggers, Ambient microphone stream capture, SMS extraction tracking, Call record listings, Target contact lifting, Internal keyboard keylogger engines, Basic command shell execution.
i-spy Android CLI • JohnReagan/i-spy-android Standardized deployment for camera frame capturing, GPS location triangulation, File system storage read/write.
Joanap APT Botnet N/A Microphone streaming, Distributed botnet tasks, Comprehensive diagnostic and credential system log theft.
Joker Play Store Injector N/A Stealth SMS/Call/Contact extraction, Local storage access, Background premium subscription manipulation (financial theft).
KevDroid CLI N/A Installed package enumeration, Phone identification metadata (IMEI/UUID), Forced 10s GPS tracking cycles, Contact/SMS/Call/Mail scraping, Local storage harvesting, Audio mic recorder.
Lab-RATS Web Interface / GUI • K4N3CO/Lab-RATS Covert screen mirroring & control, Live camera stream/snap/record, Nightmode(Camera) Keylogging, SMS & MMS view/send, Functional app decoys, Live GPS, Ghost mechanics, Blackout mode, Self healing, Remote dialer & call record, Call logs, Live microphone stream, Contacts, Remote server restart(SMS prompt), Credential Highlighting, Storage Access, Anti-removal Sheild, Notification Sniffer (WhatsApp, Telegram etc..)
LaRAT CLI • c4wrd/LaRat Message database extraction, Remote screenshot taking, Live camera access, Google Forms phishing integration for password grabbing.
LodaRAT Surveillance Vector N/A Complete camera/microphone control, Voice call routing metrics, Local file storage traversal, GPS telemetry logging, Application installation, Saved account credential extraction.
LokiDroid GUI N/A Comprehensive SMS/Call extraction, UI manipulation (Toasts/Browser), Hardware/SIM data, HTTP C2 control layer (bypasses port-forwarding constraints), Multi-bot offline command parsing.
Trojan Name UI / Interface Type Project Links / Repositories Core Features & Permissions
Mass RAT CLI • NYAN-x-CAT/Mass-RAT Background SMS harvesting, Call logging pipelines, Local filesystem storage access, Covert camera snapshots.
MMRat Exploitation Tool N/A Specialized accessibility keylogger engine, Real-time screen streaming/recording, Multi-threaded automated ADB execution arrays.
Monokle Surveillance Tool N/A Precise GPS logging, Continuous call and room audio recording, Screen recording frames, Fingerprint/Keylogger asset duplication, Browser/Mail logs, Local SMS/Call synthesis, Root privilege execution shell.
NetWire GUI Client N/A (Commercial) Camera access, Audio capture, Native keylogger, Storage access, File upload/download pipelines, GPS location monitoring.
Nexus Banking / Info RAT N/A Broad file storage parsing, Camera deployment, Ambient audio capturing, Full SMS/Call logging, Remote command shell environment, GPS tracking arrays, Multi-mode keylogger, Real-time financial/banking overlay injection, Crypto wallet access hooks, 2FA authenticator database harvesting.
Nivistealer Web-Based Stealer • swagkarna/Nivistealer Network IP resolution tracking, GPS tracking arrays, Local hardware environment diagnostics, Camera triggers, Clipboard text hijacking, Web panel deployment for fake overlay phishing.
OmniRAT GUI N/A (Commercial) Full remote access shell, File manager, App installation, Widget manipulation, System hardware information, Call/SMS management.
Pegasus High-Tier Spyware • 9aylas/Pegasus-samples
• jonathandata1/pegasus_spyware
Storage/Mic/GPS tapping, Screenshots, Calendar database access, IM apps tracking (WhatsApp, Signal, etc.), Contacts/Mail/SMS dumping, Browser history, Baseband/Device configurations.
PounceKeys Stealth Keylogger • NullPounce/pounce-keys Absolute launcher app icon concealment (Stealth mode), Persistent input keylogger engine, Baseband/Hardware identity collection, Live application notification harvesting, Clipboard framework memory scraping.
Pupy CLI • n1nj4sec/pupy Cross-platform payload, Text-to-speech injection, Dual webcam (front/back) snapshots, GPS tracking arrays.
Rafel RAT Modular Botnet • swagkarna/Rafel-Rat GPS mapping, Local file harvesting, Camera snapshot hooks, Ambient audio scraping, Phone communication status triggers, Ransomware module (Storage encryption capabilities), Comprehensive browser history exfiltration, Persistent startup mechanisms.
rdroid CLI • m301/rdroid Contact harvesting, System info, App control, Storage access, Call/Message extraction, Interactive reverse shell.
Rogue RAT Spyware Framework N/A Covert camera triggers, Live ambient audio streaming, Storage directory scraping, GPS location tracking, Native software keylogging engines.
SHConnect CLI N/A Remote camera triggers, GPS tracking, Storage directory traversal.
SpyApp Client GUI • ghazikr/SpyAppClient Notification interception listener (Facebook, WhatsApp, Instagram, Emails), System contacts, SMS monitoring, Call history logs.
SpyNote GUI N/A (Commercial/Leaked) App binding, Storage, GPS, SMS/Calls/Contacts, Camera, Live microphone streaming/recording, Browser history, System hardware data (IMEI, MAC, Carrier), "Fun Panel" interaction.
Steaelite RAT Cryptographic Vector N/A Persistent background keylogger engines, Local directory architecture harvesting, Integrated system locking/Ransomware modules.
Strandhogg Vulnerability Exploit N/A Task-affinity session hijacking, Comprehensive app log mining, Broad Android runtime permission acquisition via injection.
StrongPity APT Spyware Vector N/A Persistent GPS background tracking, Local file structure mapping, Phone system operations tracking, Boot-persistence hooks, Detailed carrier/network metadata exfiltration.
TalentRAT CLI / Payload • honglvt/TalentRAT Core SMS monitoring, Remote call generation, Contact extraction, Continuous GPS polling, Real-time camera frames and microphone audio tracking.
TearDroid PHP PHP Web Panel • ScRiPt1337/Teardroid-phprat Contacts, SMS, and active system service queries, Device location extraction (Active window constraint on SDK 29+), Dynamic shell command pipelines (e.g., findphno, findx:pdf), Wallpaper manipulation, Forced calls and SMS generation.
TecSpy Administrative RAT • bmshifat/TecSpy Comprehensive communication harvesting (SMS, Calls, Contacts), Active GPS location tracking, Local filesystem manipulation, System notification stream capturing, Clipboard memory scraping, Remote administrative ADB command execution.
TeleRAT / IIRAT Telegram C2 Interface N/A Clipboard hijacking, Process tracking, SMS/Contacts theft, Storage access, Microphone/Camera scraping, Device Admin screen capture, Vibration injection.
TheFatRAT CLI / Payload Generator • Screetsec/TheFatRat Arbitrary command execution, Process manipulation, Camera snapping/streaming, Microphone capture.
Triout Framework Framework N/A Automatic voice call recording/exfiltration to C2, SMS/Call log interception, Persistent media theft, Stealth app-icon hiding.
UnknownRAT GUI N/A Storage access, Custom Android deployment tools (photo snap, screenshot), Audio recording.
WH-RAT GUI Panel • wh-Cyberspace/WH-RAT Leaked variant structurally tied to SpyNote/NjRAT architectures. (Detailed telemetry payloads under expansion).
Xenomorph / GODFather / PixPirate / Sova / Zanubis / BingoMod / TrickMo / BlankBot / Vultur / Octo2 / Medusa Advanced Banking Trojans N/A (Active Threat Campaigns) Complete Device Takeover (ATS / Accessibility Services Abuse), Persistent Device Administrator escalation, External/Internal storage traversal, Direct automated ADB framework execution, Complete text tracking (SMS, Web notification mirroring), Installed app enumeration, Real-time automated injection templates (Phishing/Overlays), Bypasses standard biometric/PIN locks.
ZeroDayRAT Stealer Vector N/A Real-time SMS interception, Call routing details extraction, Active input keylogger module, Camera deployment, Microphone environment scraping, Baseband device profiles enumeration, Cryptographic wallet asset stealer.

🔱 Project Evolution & Acknowledgments

This repository is an updated, restructured, and actively maintained evolution of the original project by wishihab

Why this Fork exists:

  • Active Maintenance: Tracking modern Android threats up to Android SDK 36 (OneUI 8.5+).
  • Enhanced Scannability: Restructured from loose bulleted lists into high-density Markdown directories.
  • Telemetry Data: Integrating deeper structural permissions, capability matrices, and architectural markers.

🤝 Contributing to the New Directory

Because this is a completely overhauled and expanded version of the database, your contributions are vital to keeping it accurate!

Whether you want to add a modern malware strain, patch an incorrect permission metric, or fix a broken upstream link:

  1. Fork this repository.
  2. Create your branch (git checkout -b patch/Add-New-RAT).
  3. Follow our updated high-density data matrix layout.
  4. Submit a Pull Request targeting our master branch.

⚖️ Legal & Ethical Disclaimer

Warning

This directory is published entirely for informational, educational, and defensive malware research purposes.

The maintainers of both the original repository and this evolved fork DO NOT condone, encourage, or support the deployment of Remote Access Trojans (RATs), spyware, or any unauthorized surveillance tools.

Under NO circumstances shall the current or past maintainers of this information be held liable for any misuse, device damage, or legal consequences resulting from the deployment, execution, or modification of the software documented in this directory.

About

This repository serves as a comprehensive documentation directory of known Android Remote Access Trojans (RATs), compiling free, commercial, open-source, and leaked variants alongside their core tracking payloads, features, and systemic permission requirements.

Resources

Stars

6 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors