This repository serves as a comprehensive documentation directory of known Android Remote Access Trojans (RATs), compiling free, commercial, open-source, and leaked variants alongside their core tracking payloads, features, and systemic permission requirements.
Important
Educational & Research Purpose Only: This information is intended strictly for security researchers, malware analysts, and educational documentation.
Caution
HIGH INFECTION RISK: DO NOT download, compile, or execute these projects unless you fully understand the systemic risks involved.
- There is an exceptionally high risk of being infected by the tools/builders themselves.
- Always leverage isolated sandboxes (VMs/Emulators) and thoroughly inspect all source code or executables.
- Remember: A Trojan hidden inside a Trojan builder is a highly common delivery vector.
Additional archived references and general trojan documentation can be found here:
- Dataset Archive: Access the broader telemetry dataset via the Android RAT Dataset.
- Network Testing: If you require port forwarding without purchasing a VPN or modifying local router rules, utilize Ngrok.
The following ranking lists the Top 10 Android Remote Access Trojans documented in this directory, ordered by their total number of verified functional features & remote capabilities.
Score: 15/21 Checkmarks
Known Link: https://github.com/K4N3CO/Lab-RATS
- Verified Matrix Checks: GUI(PC/Mobile), Camera, Mic, SMS, MMS, Contact, Call, Call Logs, Storage, Location, Screenshot, Notification, Keylogger, Remote Takeover, Stealth Mode, and more.
- Infrastructure Edge: Bypasses classic port-forwarding constraints entirely by utilizing native IPv6 direct traversal pipelines. Optimized to support modern target testing layouts all the way up to Android SDK 36 (OneUI 8.5+).
Score: 12/21 Checkmarks
- Verified Matrix Checks: GUI, Camera, Mic, SMS, Contact, Call, Call Logs, Storage, Location, Browser, App List, Notification.
- Infrastructure Edge: Heavily optimized for system-wide sensory dominance. It handles direct payload app-binding, extracts environmental audio loops, and traces hidden hardware telemetry (IMEI/WIFI MAC).
Score: 11/21 Checkmarks
Known Link: https://github.com/saksham2410/Android-RAT---Hawkshaw
- Verified Matrix Checks: Camera, Mic, SMS, Contact, Call, Storage, Location, Account Detail, Lock/Vibrate/Flash, App Management, Keylogger.
- Infrastructure Edge: Optimizes persistent data pipelines and social log exfiltration points, ensuring high tracking density directly following reboot sequences.
Score: 10/21 Checkmarks
- Verified Matrix Checks: GUI, Camera, Mic, SMS, Contact, Call, Call Logs, Storage, Location, Browser.
- Infrastructure Edge: Designed as a multi-bot HTTP client that removes port-forwarding constraints through an asynchronous web C2 control platform.
Score: 10/21 Checkmarks
- Verified Matrix Checks: GUI, Mic, SMS, Contact, Storage, Location, App List, Admin Control, Inject, Phishing.
- Infrastructure Edge: A highly destructive financial botnet engine designed for systemic mobile banking takeover. It uses a specialized commercial control panel to coordinate real-time overlay delivery across thousands of distributed zombie targets.
Score: 10/21 Checkmarks
- Verified Matrix Checks: Camera, Mic, SMS, Contact, Call, Call Logs, Storage, App List, Screenshot, Shell.
- Infrastructure Edge: A dual-threat exploitation framework merging continuous surveillance loops with an automated system-locking Ransomware module.
Score: 10/21 Checkmarks
- Verified Matrix Checks: GUI, Camera, Mic, SMS, Contact, Call, Storage, Location, Browser, App List.
- Infrastructure Edge: The historical reference baseline for Android monitoring tools. Maps complete local directories and captures intact WhatsApp messaging databases.
Score: 9/21 Checkmarks
Known Link: https://github.com/CanciuCostin/android-spyware
- Verified Matrix Checks: SMS, Call, Contact, Device Info, App List (Install Apps), App List (Get Apps), WebView Inject, Camera, Storage, Mic, ADB Command Control.
- Infrastructure Edge: Offers a dense, raw framework that focuses heavily on sensory extraction and deep background system control via automated low-level ADB shell injection.
Score: 9/21 Checkmarks
- Verified Matrix Checks: Camera, Mic, SMS, Call, Storage, Location, Keylogger, Shell, Inject.
- Infrastructure Edge: A sophisticated threat focused on financial target exploitation, automating crypto-wallet hijacking, web overlay phishing injection, and 2FA authenticator database harvesting.
Score: 9/21 Checkmarks
Known Link: https://github.com/AhMyth/AhMyth-Android-RAT
- Verified Matrix Checks: GUI, Camera, Mic, SMS, Contact, Call, Call Logs, Storage, Location.
- Infrastructure Edge: A lightweight open-source framework frequently used as an analytical baseline for background media exfiltration and continuous GPS polling loops.
| Name | GUI | OS | Camera | Mic | SMS | MMS | Contacts | Call | Call Logs | Storage | Location | Browser | App List | Admin Control | Keylogger | Screenshot | Shell | Notification | Remote Takeover | Inject | Phishing | Stealth Mode | GitHub Link | Special Feature |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Adobot | ❌ | 🐧💻 | ❌ | ❌ | ✔️ | ❌ | ✔️ | ✔️ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ✔️ | ❌ | ❌ | ❌ | ❌ | ✔️ | ✔️ | https://github.com/adonespitogo/AdoBot | Realtime command execution, Schedule commands |
| AhMyth | ✔️ | 🐧💻 | ✔️ | ✔️ | ✔️ | ❌ | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | https://github.com/AhMyth/AhMyth-Android-RAT | - |
| AIRAVAT | ❌ | 🐧💻 | ✔️ | ✔️ | ✔️ | ❌ | ✔️ | ✔️ | ✔️ | ❌ | ❌ | ✔️ | ✔️ | ❌ | ✔️ | ✔️ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | https://github.com/Th30neAnd0nly/AIRAVAT https://github.com/GoutamHX/MAXXRAT |
Ransomware, Shell Command |
| Android Spy App | ❌ | 🐧💻 | ❌ | ❌ | ✔️ | ❌ | ✔️ | ✔️ | ✔️ | ✔️ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | https://github.com/abhinavsuthar/Android_Spy_App | Logs |
| Android Spyware | ❌ | 🐧💻 | ✔️ | ✔️ | ✔️ | ❌ | ✔️ | ✔️ | ✔️ | ❌ | ❌ | ✔️ | ❌ | ❌ | ❌ | ✔️ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | https://github.com/CanciuCostin/android-spyware | Adb command control |
| android_trojan | ❌ | 🐧💻 | ❌ | ✔️ | ✔️ | ❌ | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ | ❌ | ❌ | ❌ | ✔️ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | https://github.com/androidtrojan1/android_trojan | Browser history, Add/remove app |
| Android Voyage | ❌ | 🐧💻 | ❌ | ❌ | ✔️ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ✔️ | ✔️ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ✔️ | - | Remote Screen, Traffic monitor, System app, Lock/unlock, Hide app, Remove password, Brick device, Anti Antivirus, Self Destructive, Password Grabbers |
| AndroRAT | ✔️ | 🐧💻 | ✔️ | ✔️ | ✔️ | ❌ | ✔️ | ✔️ | ❌ | ✔️ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | https://github.com/DesignativeDave/androrat https://github.com/karma9874/AndroRAT https://github.com/The404Hacking/AndroRAT |
Streaming Video, Toast, Vibrate, Open URL |
| AndroSpy | ❌ | 🐧💻 | ✔️ | ❌ | ✔️ | ❌ | ✔️ | ❌ | ✔️ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | https://github.com/qH0sT/AndroSpy | Install, Inject |
| Arsink RAT | ❌ | 🐧💻 | ❌ | ❌ | ✔️ | ❌ | ✔️ | ❌ | ❌ | ✔️ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ✔️ | ❌ | ❌ | - | Sniff, Phishing |
| BetterAndroRAT | ❌ | 🐧💻 | ✔️ | ✔️ | ✔️ | ❌ | ✔️ | ✔️ | ✔️ | ✔️ | ❌ | ✔️ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | https://github.com/mwsrc/BetterAndroRAT | Add/remove app, Remote Device Controller |
| Name | GUI | OS | Camera | Mic | SMS | MMS | Contacts | Call | Call Logs | Storage | Location | Browser | App List | Admin Control | Keylogger | Screenshot | Shell | Notification | Remote Takeover | Inject | Phishing | Stealth Mode | GitHub Link | Special Feature |
| BlueEagle jRAT | ❌ | 🐧💻 | ✔️ | ✔️ | ✔️ | ❌ | ✔️ | ❌ | ✔️ | ✔️ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | - | Phone Information, Account Detail, Owner Access (Boot), Block google protect |
| BRAT | ❌ | 🐧💻 | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ✔️ | ✔️ | ❌ | ❌ | ❌ | ❌ | ❌ | ✔️ | ❌ | ❌ | ❌ | - | Install and remove apps, Factory Reset |
| Casperspy | ✔️ | 🐧💻 | ✔️ | ✔️ | ✔️ | ❌ | ❌ | ❌ | ✔️ | ❌ | ✔️ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | https://github.com/dhanumurti | Botnet by dendroid, Browser open page |
| Cerberus App | ❌ | 🐧💻 | ✔️ | ❌ | ❌ | ❌ | ❌ | ❌ | ✔️ | ✔️ | ❌ | ❌ | ✔️ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | - | Not deletable |
| Cerberus Bank | ✔️ | 🐧💻 | ❌ | ✔️ | ✔️ | ❌ | ✔️ | ❌ | ❌ | ✔️ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | - | Bank and CC Logs, Mail logs, Turnoff Play Protected, Download/Install/Remove Apps, Lock device |
| Chameleon | ❌ | 🐧💻 | ❌ | ❌ | ✔️ | ❌ | ✔️ | ❌ | ✔️ | ❌ | ❌ | ❌ | ❌ | ✔️ | ✔️ | ❌ | ❌ | ❌ | ❌ | ✔️ | ❌ | ❌ | - | Screen Capture, Overlay, Proxy, Cookies Stealer |
| columbus-trojan | ❌ | 🐧💻 | ✔️ | ✔️ | ❌ | ❌ | ❌ | ❌ | ❌ | ✔️ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | https://github.com/project-columbus/trojan | Front-facing camera, 10s sound clip, Mobile triangulation |
| Darkweb PexRat | ❌ | 🐧💻 | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ✔️ | ❌ | ✔️ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | - | Screen, Infostealer |
| Dash | ✔️ | 🐧💻 | ✔️ | ❌ | ✔️ | ❌ | ✔️ | ✔️ | ❌ | ✔️ | ❌ | ❌ | ❌ | ❌ | ✔️ | ❌ | ❌ | ✔️ | ❌ | ❌ | ✔️ | ✔️ | https://github.com/muneebwanee/Dash | Multiple Child clients, Environment recording, Notifications received |
| Dendroid | ❌ | 🐧💻 | ✔️ | ❌ | ✔️ | ❌ | ✔️ | ✔️ | ❌ | ❌ | ✔️ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | https://github.com/nyx0/Dendroid | Opening web pages, Uploading images/video, Denial-of-service, Change C&C server |
| DogeRAT | ❌ | 🐧💻 | ✔️ | ❌ | ✔️ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ✔️ | ✔️ | ✔️ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | - | Install/remove apps, GetApps, Inject |
| Name | GUI | OS | Camera | Mic | SMS | MMS | Contacts | Call | Call Logs | Storage | Location | Browser | App List | Admin Control | Keylogger | Screenshot | Shell | Notification | Remote Takeover | Inject | Phishing | Stealth Mode | GitHub Link | Special Feature |
| DroidJack | ✔️ | 🐧💻 | ✔️ | ✔️ | ✔️ | ❌ | ✔️ | ❌ | ✔️ | ✔️ | ✔️ | ✔️ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | - | Whatsapp Reader, Browser History, App Manager |
| ERMAC | ❌ | 🐧💻 | ❌ | ❌ | ✔️ | ❌ | ✔️ | ❌ | ❌ | ❌ | ❌ | ✔️ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | - | InstallApps, GetApps |
| Fantasy Hub | ❌ | 🐧💻 | ✔️ | ✔️ | ✔️ | ❌ | ✔️ | ❌ | ✔️ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | - | 2FA, Realtime Cam/Mic, Permission runtime |
| FinSpy | ❌ | 🐧💻 | ❌ | ✔️ | ✔️ | ❌ | ✔️ | ❌ | ✔️ | ✔️ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | - | Phone information, Mms, Voip record (Skype, WeChat, Viber, LINE) |
| GhostCtrl | ❌ | 🐧💻 | ❌ | ✔️ | ✔️ | ❌ | ❌ | ❌ | ❌ | ✔️ | ❌ | ❌ | ✔️ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | - | Voice record |
| Gigabud RAT | ❌ | 🐧💻 | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ✔️ | ❌ | ❌ | ❌ | ❌ | ✔️ | ✔️ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | - | Screen record, Install package |
| GoldDigger | ❌ | 🐧💻 | ❌ | ❌ | ✔️ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ✔️ | ✔️ | ❌ | ❌ | ❌ | ❌ | ✔️ | ❌ | ❌ | - | - |
| GravityRAT | ❌ | 🐧💻 | ❌ | ❌ | ✔️ | ❌ | ✔️ | ❌ | ✔️ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | - | Exfiltrate data |
| HaxRAT | ❌ | 🐧💻 | ✔️ | ✔️ | ❌ | ❌ | ❌ | ❌ | ✔️ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | https://github.com/Hax4us/haxRat | Audio recording |
| Hawkshaw | ❌ | 🐧💻 | ✔️ | ✔️ | ✔️ | ❌ | ✔️ | ❌ | ✔️ | ✔️ | ❌ | ❌ | ❌ | ✔️ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ✔️ | ❌ | https://github.com/saksham2410/Android-RAT---Hawkshaw | Account Detail, Lock, Vibrate, Flash, Owner Access (Boot), Inject, Logs/Keylog (messenger, socialmedia) |
| Name | GUI | OS | Camera | Mic | SMS | MMS | Contacts | Call | Call Logs | Storage | Location | Browser | App List | Admin Control | Keylogger | Screenshot | Shell | Notification | Remote Takeover | Inject | Phishing | Stealth Mode | GitHub Link | Special Feature |
| Hector / ISOON | ❌ | 🐧💻 | ❌ | ❌ | ✔️ | ❌ | ✔️ | ❌ | ✔️ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | - | Log system multi platform, adb control |
| Hidden Cobra | ❌ | 🐧💻 | ❌ | ❌ | ✔️ | ❌ | ✔️ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | - | Proxy, Payload |
| HighRise | ❌ | 🐧💻 | ❌ | ❌ | ✔️ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | - | Incoming/outgoing SMS |
| IMG-RAT | ❌ | 🐧💻 | ✔️ | ✔️ | ✔️ | ❌ | ✔️ | ❌ | ✔️ | ❌ | ❌ | ❌ | ❌ | ✔️ | ❌ | ✔️ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | - | Shell integration |
| i-spy Android | ❌ | 🐧💻 | ✔️ | ❌ | ❌ | ❌ | ❌ | ❌ | ✔️ | ✔️ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | https://github.com/JohnReagan/i-spy-android | Standard filesystem storage |
| Joanap | ❌ | 🐧💻 | ❌ | ✔️ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | - | Botnet, Steal log |
| Joker | ❌ | 🐧💻 | ❌ | ❌ | ✔️ | ❌ | ✔️ | ❌ | ✔️ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | - | Manipulating subscription (money), Play Store infection |
| KevDroid | ❌ | 🐧💻 | ❌ | ✔️ | ✔️ | ❌ | ✔️ | ✔️ | ✔️ | ✔️ | ❌ | ✔️ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | - | Installed apps, Phone number, Unique ID, Mails |
| Lab-RATS | ✔️ | 🐧💻🍎 | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ | ❌ | ❌ | ❌ | ✔️ | ✔️ | ❌ | ✔️ | ✔️ | ❌ | ❌ | ✔️ | https://github.com/K4N3CO/Lab-RATS | IPv6 traversal, Works on Newest Android(SDK 36), Blackout Mode(screen blinding), Remote App Restart(SMS Prompt), Anti-Removal Sheild, Ghost Mechanics, Self Healing, Functional App Decoys. |
| LaRAT | ❌ | 🐧💻 | ✔️ | ❌ | ✔️ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ✔️ | ❌ | ❌ | ❌ | ❌ | ✔️ | ❌ | ❌ | https://github.com/c4wrd/LaRat | Add Google form for passwords |
| LodaRAT | ❌ | 🐧💻 | ✔️ | ✔️ | ❌ | ❌ | ✔️ | ❌ | ✔️ | ✔️ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | - | Install application, Account Credentials |
| Name | GUI | OS | Camera | Mic | SMS | MMS | Contacts | Call | Call Logs | Storage | Location | Browser | App List | Admin Control | Keylogger | Screenshot | Shell | Notification | Remote Takeover | Inject | Phishing | Stealth Mode | GitHub Link | Special Feature |
| LokiDroid | ✔️ | 🐧💻 | ✔️ | ✔️ | ✔️ | ❌ | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | - | Phone details, Sim/Internet details, Offline commands, Multiple bots, http RAT |
| Mass RAT | ❌ | 🐧💻 | ✔️ | ❌ | ✔️ | ❌ | ✔️ | ❌ | ✔️ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | https://github.com/NYAN-x-CAT/Mass-RAT | - |
| MMRat | ❌ | 🐧💻 | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ✔️ | ✔️ | ✔️ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | - | adb command automation |
| Monokle | ❌ | 🐧💻 | ❌ | ✔️ | ✔️ | ❌ | ✔️ | ✔️ | ❌ | ✔️ | ✔️ | ❌ | ❌ | ✔️ | ✔️ | ✔️ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | - | Screen recording, Fingerprint-device duplicate, Shell as root |
| NetWire | ✔️ | 🐧💻 | ✔️ | ✔️ | ❌ | ❌ | ❌ | ❌ | ✔️ | ✔️ | ❌ | ❌ | ❌ | ✔️ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | - | Download/Upload pipelines |
| Nexus | ❌ | 🐧💻 | ✔️ | ✔️ | ✔️ | ❌ | ✔️ | ❌ | ✔️ | ✔️ | ❌ | ❌ | ❌ | ✔️ | ❌ | ✔️ | ❌ | ❌ | ❌ | ✔️ | ❌ | ❌ | - | Inject Banking, Crypto app, 2FA app database |
| Nivistealer | ❌ | 🐧💻 | ✔️ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ✔️ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ✔️ | ❌ | ❌ | https://github.com/swagkarna/Nivistealer | IP, Web steal based, set phishing site |
| OmniRAT | ✔️ | 🐧💻 | ❌ | ❌ | ✔️ | ❌ | ✔️ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ✔️ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | - | Full Remote Access, File Manager, App Widgets, Full System Information |
| Pegasus | ❌ | 🐧💻🍎 | ❌ | ✔️ | ✔️ | ❌ | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ | ❌ | ❌ | ❌ | ✔️ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | https://github.com/9aylas/Pegasus-samples https://github.com/jonathandata1/pegasus_spyware |
Calendar, Instant Messaging, Mail, Device Setting |
| PounceKeys | ❌ | 🐧💻 | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ✔️ | ❌ | ❌ | ✔️ | ❌ | ❌ | ❌ | ✔️ | ❌ | https://github.com/NullPounce/pounce-keys | Phone info extraction, clipboard memory scraping |
| Pupy | ❌ | 🐧💻 | ✔️ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ✔️ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | https://github.com/n1nj4sec/pupy | Text to speech, Webcam snapshots (front & back) |
| Name | GUI | OS | Camera | Mic | SMS | MMS | Contacts | Call | Call Logs | Storage | Location | Browser | App List | Admin Control | Keylogger | Screenshot | Shell | Notification | Remote Takeover | Inject | Phishing | Stealth Mode | GitHub Link | Special Feature |
| Rafel RAT | ❌ | 🐧💻 | ✔️ | ✔️ | ❌ | ❌ | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ | ❌ | ✔️ | ❌ | ❌ | ❌ | ✔️ | ❌ | ❌ | ❌ | ❌ | ❌ | github.com/swagkarna/Rafel-Rat | Ransomware module, Persistence mechanisms |
| rdroid | ❌ | 🐧💻 | ❌ | ❌ | ✔️ | ❌ | ✔️ | ❌ | ✔️ | ❌ | ❌ | ✔️ | ❌ | ❌ | ❌ | ✔️ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | github.com | System diagnostics |
| Rogue RAT | ❌ | 🐧💻 | ✔️ | ✔️ | ❌ | ❌ | ❌ | ❌ | ✔️ | ✔️ | ❌ | ❌ | ❌ | ✔️ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | - | Continuous telemetry |
| SHConnect | ❌ | 🐧💻 | ✔️ | ❌ | ❌ | ❌ | ❌ | ❌ | ✔️ | ✔️ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | - | Basic tracking |
| SpyApp Client | ✔️ | 🐧💻 | ❌ | ❌ | ✔️ | ❌ | ✔️ | ✔️ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ✔️ | ❌ | ❌ | ❌ | ❌ | ❌ | github.com/ghazikr/SpyAppClient | Notification Listener (Facebook, whatsapp, instagram etc) |
| SpyNote | ✔️ | 🐧💻 | ✔️ | ✔️ | ✔️ | ❌ | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | - | Bind app, Live mic streaming/recording, Hardware details, Fun Panel |
| Steaelite RAT | ❌ | 🐧💻 | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ✔️ | ❌ | ❌ | ❌ | ❌ | ✔️ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | - | Ransomware |
| Strandhogg | ❌ | 🐧💻 | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | - | Hijack Session, apps log, wide permission injection |
| StrongPity | ❌ | 🐧💻 | ❌ | ❌ | ❌ | ❌ | ✔️ | ❌ | ✔️ | ✔️ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | - | Boot, Network Info tracking |
| TalentRAT | ❌ | 🐧💻 | ✔️ | ✔️ | ✔️ | ❌ | ✔️ | ❌ | ❌ | ✔️ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | github.com/honglvt/TalentRAT | - |
| TearDroid PHP | ❌ | 🐧💻 | ❌ | ❌ | ✔️ | ❌ | ✔️ | ✔️ | ❌ | ✔️ | ❌ | ✔️ | ❌ | ❌ | ❌ | ✔️ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | github.com/ScRiPt1337/Teardroid-phprat | Running Services tracker, findphno/findx:pdf command integration, Change Wallpaper |
| TecSpy | ❌ | 🐧💻 | ❌ | ❌ | ✔️ | ❌ | ✔️ | ❌ | ✔️ | ✔️ | ❌ | ❌ | ✔️ | ❌ | ❌ | ✔️ | ✔️ | ✔️ | ❌ | ❌ | ❌ | ❌ | github.com | Notification logger, Admin adb operations |
| Name | GUI | OS | Camera | Mic | SMS | MMS | Contacts | Call | Call Logs | Storage | Location | Browser | App List | Admin Control | Keylogger | Screenshot | Shell | Notification | Remote Takeover | Inject | Phishing | Stealth Mode | GitHub Link | Special Feature |
| TeleRAT/IIRAT | ❌ | 🐧💻 | ✔️ | ✔️ | ✔️ | ❌ | ✔️ | ❌ | ✔️ | ❌ | ❌ | ✔️ | ✔️ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | - | Telegram BOT integration, Control Admin Screen, Vibrate |
| TheFatRAT | ❌ | 🐧💻🍎 | ✔️ | ✔️ | ❌ | ❌ | ❌ | ❌ | ✔️ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ✔️ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | github.com/Screetsec/TheFatRat | Execute command, process list optimization |
| Triout Framework | ❌ | 🐧💻 | ✔️ | ❌ | ✔️ | ❌ | ❌ | ✔️ | ✔️ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ✔️ | ✔️ | - | Record phonecall, Steal images/video, Hide app icon |
| UnknownRAT | ✔️ | 🐧💻 | ✔️ | ✔️ | ❌ | ❌ | ❌ | ❌ | ✔️ | ❌ | ❌ | ❌ | ❌ | ❌ | ✔️ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | - | Android Tools (photo, screenshot), Record audio |
| WH-RAT | ✔️ | 🐧💻 | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | github.com | Similar with SpyNote NjRAT |
| Xenomorph / GODFather / PixPirate / Sova / Zanubis / BingoMod / TrickMo / BlankBot / Vultur / Octo2 / Medusa | ❌ | 🐧💻 | ✔️ | ❌ | ✔️ | ❌ | ❌ | ❌ | ✔️ | ❌ | ❌ | ✔️ | ✔️ | ❌ | ❌ | ✔️ | ✔️ | ❌ | ❌ | ✔️ | ❌ | ❌ | - | Fully Control Device, Overlay systems, Bypasses standard biometric/PIN locks |
| ZeroDayRAT | ❌ | 🐧💻 | ✔️ | ✔️ | ✔️ | ❌ | ✔️ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ✔️ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | - | Cryptostealer, Device info profiles |
| Trojan Name | UI / Interface Type | Project Links / Repositories | Core Features & Permissions |
|---|---|---|---|
| Adobot | CLI Tracker | • adonespitogo/AdoBot | Real-time command loop execution, Cron/Scheduled commands, Icon concealment (Stealth mode), Contacts/SMS/Call logs extraction. |
| AhMyth | GUI | • AhMyth/AhMyth-Android-RAT | Camera, Microphone, Storage, GPS tracker, SMS interception, Call log extraction, Contacts dumping. |
| AIRAVAT | CLI / Payload | • Th30neAnd0nly/AIRAVAT • GoutamHX/MAXXRAT |
Direct filesystem storage parsing, Device Administrator permission hooks, App listing vectors, Complete communication mining (SMS/Call/Contacts), Front/Back camera capture, Ambient microphone scraping, Remote screen capture pipelines, System-locking Ransomware payload, Interactive remote shell environment. |
| Android Spy App | CLI | • abhinavsuthar/Android_Spy_App | Contacts/Call logs/SMS data mining, General diagnostic logs, GPS tracker, External storage access. |
| Android Spyware | Comprehensive Framework | • CanciuCostin/android-spyware | Complete communication logging (SMS/Call/Contacts), System information mapping, App package indexing/installation, WebView credential injection, Camera capture, Local storage parsing, Microphone capture, Arbitrary ADB shell command execution. |
| Android Trojan | CLI | • androidtrojan1/android_trojan | Interactive shell, Browser history, Microphone, GPS tracking, Storage, App management, Contacts/SMS/Call log dumping. |
| Android Voyage | CLI | N/A | Remote screen mirroring, Screenshots, Keylogging, Traffic monitoring, Persistent system app conversion, Passcode removal, Anti-Antivirus mechanics, Self-destructive mode, Credential grabbers. |
| AndroRAT | GUI Available | • DesignativeDave/androrat • karma9874/AndroRAT • The404Hacking/AndroRAT |
Contacts, Call logs, SMS, GPS, Camera, Mic, Live video streaming, UI Toast messages, URL redirection, Device vibration. |
| AndroSpy | CLI | • qH0sT/AndroSpy | Camera triggers, SMS monitoring, Contact extraction, Call history harvesting, Local storage read/write access, Arbitrary package installation and code injection. |
| Arsink RAT | Spyware Vector | N/A | Complete text parsing (SMS channels), Contact data scraping, Voice call logging pipelines, GPS path mapping, Local network traffic sniffing, Custom social application overlay phishing. |
| BetterAndroRAT | CLI | • mwsrc/BetterAndroRAT | Package installation/removal, Camera, Microphone, Storage access, Call & SMS routing, Remote hardware controller. |
| BlueEagle jRAT | Desktop Client Link | N/A | Call/SMS/Contact monitoring, Core system data mining, Camera frame capture, Ambient audio capture, Real-time location parsing, Target account info tracking, Boot persistence hooks, Google Play Protect disabling functions. |
| BRAT | Brazilian Banking RAT | N/A | Silently installs/uninstalls application layers, Package enumeration, Credential injection modules, Force factory reset execution, Device Administrator privilege hijacking. |
| Casperspy | GUI Botnet | • dhanumurti | Dendroid-derived botnet architecture, SMS logging, Camera/Storage/Microphone tracking, Remote browser manipulation. |
| Cerberus App | Admin Client | N/A | Storage access, Real-time GPS location, Camera triggers, Admin privilege persistence, Anti-uninstallation hooks. |
| Cerberus Banking | GUI Panel | N/A | Botnet overlay mechanics, Core banking/Credit Card credential logging, Mail database harvesting, Call forwarding injection, Audio/SMS/GPS trackers, Play Protect security disabling, Remote application installer/remover, Hard screen lock. |
| Chameleon | Advanced Stealer | N/A | Target layout phishing templates, Automated system keylogger engine, Contact/SMS/Call tracking databases, Local data storage mining, Live layout screen capture, Dynamic input field accessibility overlays, Local SOCKS proxy establishment, Browser session cookie stealing. |
| Columbus-Trojan | CLI | • project-columbus/trojan | Minimalist stealth design: Front-facing camera snap, 10-second mic audio clipping, Triangulated cell network location. |
| Darkweb PexRat | Commercial Spyware | N/A | Continuous screen capturing/mirroring framework, Device Administrator validation enforcement, Distributed infostealer profile modules. |
| Dash | GUI Control Panel | • muneebwanee/Dash | Integrated camera control, Multi-child client control array, Dynamic launcher icon hiding (Stealth mode), Live GPS coordinates mapping, Bi-directional call recording (Incoming/Outgoing), SMS transaction indexing, Ambient audio monitoring, Native keylogger engine, Targeted social network web phishing templates, Notification stream listeners (WhatsApp, Instagram, Messenger). |
| Dendroid | Panel Control | • nyx0/Dendroid | Full SMS/Call monitoring, Forced HTTP page opening, Remote video/image exfiltration, App initialization, Native DDoS execution panels, Dynamic C2 reassignment. |
| DogeRAT | Admin Panel Client | N/A | Stealth app package installation/uninstallation, Active package enumeration, Over-the-air injection layers, Real-time camera frames capture, SMS network monitoring, Integrated device keylogging, Full Device Administrator control. |
| DroidJack | GUI | N/A (Closed/Leaked) | Camera, Mic, GPS, Storage, SMS/Calls/Contacts, WhatsApp reader, Browser history, App manager. |
| ERMAC | Banking Botnet | N/A | Automated SMS/Call log interception, Contact database exfiltration, Installed application scanning, Package execution commands, Automated WebView overlay injection. |
| Fantasy Hub | Surveillance Toolkit | N/A | Direct text tracing (SMS pipelines), 2FA validation token interception, Target contact tracking, Real-time video/microphone parsing, Local directory data traversal, Runtime prompt permission interaction hijacking. |
| FinSpy | Commercial Spyware | N/A | Advanced storage harvesting, System metadata collection, Call/SMS/MMS extraction, GPS tracking, Native VoIP stream recording (Skype, WeChat, Viber, LINE). |
| GhostCtrl | Admin Client | N/A | Device administrator privilege escalation, Persistent voice recording, SMS routing, GPS location caching. |
| Gigabud RAT | Screen Stealer | N/A | Real-time screen recording/mirroring pipelines, Storage file extraction, Package deployment/installation hooks, Custom localized keylogging engines. |
| GoldDigger | Financial Malware | N/A | Native accessibility-driven keylogger engine, Screen layout scraping, Transaction text SMS interception, Target banking web overlay phishing templates. |
| GravityRAT | Targeted Spyware | N/A | Background SMS mining, Contact exfiltration, Call log interceptor, Mass system folder exfiltration routines. |
| HaxRAT | Framework / Payload | • Hax4us/haxRat | Complete external/internal storage traversal, Direct camera control, Live room microphone capture. |
| Hawkshaw | CLI / Framework | • saksham2410/Android-RAT---Hawkshaw | Full communication log harvesting, Audio/Video/GPS capture, Device user account details theft, Hardware manipulation (Lock, vibrate, flash), Boot-persistence execution hook, Stealth app management, Messenger keylogging overlays. |
| Hector / ISOON RAT | APT / Multiplatform | N/A | Local filesystem mapping, SMS communication streams extraction, Contact logs lifting, Multi-platform unified system log engine, Low-level administrative ADB control modules. |
| Hidden Cobra | APT Payload | N/A | Network proxy hosting, Contact database lifting, SMS exploitation, Secondary malicious payload drop vectors. |
| HighRise | Background Service | N/A | Proxy-based capture of incoming and outgoing SMS traffic. |
| IMG-RAT | Payload Generator | N/A | Local directory storage traversal, Camera state triggers, Ambient microphone stream capture, SMS extraction tracking, Call record listings, Target contact lifting, Internal keyboard keylogger engines, Basic command shell execution. |
| i-spy Android | CLI | • JohnReagan/i-spy-android | Standardized deployment for camera frame capturing, GPS location triangulation, File system storage read/write. |
| Joanap | APT Botnet | N/A | Microphone streaming, Distributed botnet tasks, Comprehensive diagnostic and credential system log theft. |
| Joker | Play Store Injector | N/A | Stealth SMS/Call/Contact extraction, Local storage access, Background premium subscription manipulation (financial theft). |
| KevDroid | CLI | N/A | Installed package enumeration, Phone identification metadata (IMEI/UUID), Forced 10s GPS tracking cycles, Contact/SMS/Call/Mail scraping, Local storage harvesting, Audio mic recorder. |
| Lab-RATS | Web Interface / GUI | • K4N3CO/Lab-RATS | Covert screen mirroring & control, Live camera stream/snap/record, Nightmode(Camera) Keylogging, SMS & MMS view/send, Functional app decoys, Live GPS, Ghost mechanics, Blackout mode, Self healing, Remote dialer & call record, Call logs, Live microphone stream, Contacts, Remote server restart(SMS prompt), Credential Highlighting, Storage Access, Anti-removal Sheild, Notification Sniffer (WhatsApp, Telegram etc..) |
| LaRAT | CLI | • c4wrd/LaRat | Message database extraction, Remote screenshot taking, Live camera access, Google Forms phishing integration for password grabbing. |
| LodaRAT | Surveillance Vector | N/A | Complete camera/microphone control, Voice call routing metrics, Local file storage traversal, GPS telemetry logging, Application installation, Saved account credential extraction. |
| LokiDroid | GUI | N/A | Comprehensive SMS/Call extraction, UI manipulation (Toasts/Browser), Hardware/SIM data, HTTP C2 control layer (bypasses port-forwarding constraints), Multi-bot offline command parsing. |
| Trojan Name | UI / Interface Type | Project Links / Repositories | Core Features & Permissions |
| Mass RAT | CLI | • NYAN-x-CAT/Mass-RAT | Background SMS harvesting, Call logging pipelines, Local filesystem storage access, Covert camera snapshots. |
| MMRat | Exploitation Tool | N/A | Specialized accessibility keylogger engine, Real-time screen streaming/recording, Multi-threaded automated ADB execution arrays. |
| Monokle | Surveillance Tool | N/A | Precise GPS logging, Continuous call and room audio recording, Screen recording frames, Fingerprint/Keylogger asset duplication, Browser/Mail logs, Local SMS/Call synthesis, Root privilege execution shell. |
| NetWire | GUI Client | N/A (Commercial) | Camera access, Audio capture, Native keylogger, Storage access, File upload/download pipelines, GPS location monitoring. |
| Nexus | Banking / Info RAT | N/A | Broad file storage parsing, Camera deployment, Ambient audio capturing, Full SMS/Call logging, Remote command shell environment, GPS tracking arrays, Multi-mode keylogger, Real-time financial/banking overlay injection, Crypto wallet access hooks, 2FA authenticator database harvesting. |
| Nivistealer | Web-Based Stealer | • swagkarna/Nivistealer | Network IP resolution tracking, GPS tracking arrays, Local hardware environment diagnostics, Camera triggers, Clipboard text hijacking, Web panel deployment for fake overlay phishing. |
| OmniRAT | GUI | N/A (Commercial) | Full remote access shell, File manager, App installation, Widget manipulation, System hardware information, Call/SMS management. |
| Pegasus | High-Tier Spyware | • 9aylas/Pegasus-samples • jonathandata1/pegasus_spyware |
Storage/Mic/GPS tapping, Screenshots, Calendar database access, IM apps tracking (WhatsApp, Signal, etc.), Contacts/Mail/SMS dumping, Browser history, Baseband/Device configurations. |
| PounceKeys | Stealth Keylogger | • NullPounce/pounce-keys | Absolute launcher app icon concealment (Stealth mode), Persistent input keylogger engine, Baseband/Hardware identity collection, Live application notification harvesting, Clipboard framework memory scraping. |
| Pupy | CLI | • n1nj4sec/pupy | Cross-platform payload, Text-to-speech injection, Dual webcam (front/back) snapshots, GPS tracking arrays. |
| Rafel RAT | Modular Botnet | • swagkarna/Rafel-Rat | GPS mapping, Local file harvesting, Camera snapshot hooks, Ambient audio scraping, Phone communication status triggers, Ransomware module (Storage encryption capabilities), Comprehensive browser history exfiltration, Persistent startup mechanisms. |
| rdroid | CLI | • m301/rdroid | Contact harvesting, System info, App control, Storage access, Call/Message extraction, Interactive reverse shell. |
| Rogue RAT | Spyware Framework | N/A | Covert camera triggers, Live ambient audio streaming, Storage directory scraping, GPS location tracking, Native software keylogging engines. |
| SHConnect | CLI | N/A | Remote camera triggers, GPS tracking, Storage directory traversal. |
| SpyApp Client | GUI | • ghazikr/SpyAppClient | Notification interception listener (Facebook, WhatsApp, Instagram, Emails), System contacts, SMS monitoring, Call history logs. |
| SpyNote | GUI | N/A (Commercial/Leaked) | App binding, Storage, GPS, SMS/Calls/Contacts, Camera, Live microphone streaming/recording, Browser history, System hardware data (IMEI, MAC, Carrier), "Fun Panel" interaction. |
| Steaelite RAT | Cryptographic Vector | N/A | Persistent background keylogger engines, Local directory architecture harvesting, Integrated system locking/Ransomware modules. |
| Strandhogg | Vulnerability Exploit | N/A | Task-affinity session hijacking, Comprehensive app log mining, Broad Android runtime permission acquisition via injection. |
| StrongPity | APT Spyware Vector | N/A | Persistent GPS background tracking, Local file structure mapping, Phone system operations tracking, Boot-persistence hooks, Detailed carrier/network metadata exfiltration. |
| TalentRAT | CLI / Payload | • honglvt/TalentRAT | Core SMS monitoring, Remote call generation, Contact extraction, Continuous GPS polling, Real-time camera frames and microphone audio tracking. |
| TearDroid PHP | PHP Web Panel | • ScRiPt1337/Teardroid-phprat | Contacts, SMS, and active system service queries, Device location extraction (Active window constraint on SDK 29+), Dynamic shell command pipelines (e.g., findphno, findx:pdf), Wallpaper manipulation, Forced calls and SMS generation. |
| TecSpy | Administrative RAT | • bmshifat/TecSpy | Comprehensive communication harvesting (SMS, Calls, Contacts), Active GPS location tracking, Local filesystem manipulation, System notification stream capturing, Clipboard memory scraping, Remote administrative ADB command execution. |
| TeleRAT / IIRAT | Telegram C2 Interface | N/A | Clipboard hijacking, Process tracking, SMS/Contacts theft, Storage access, Microphone/Camera scraping, Device Admin screen capture, Vibration injection. |
| TheFatRAT | CLI / Payload Generator | • Screetsec/TheFatRat | Arbitrary command execution, Process manipulation, Camera snapping/streaming, Microphone capture. |
| Triout Framework | Framework | N/A | Automatic voice call recording/exfiltration to C2, SMS/Call log interception, Persistent media theft, Stealth app-icon hiding. |
| UnknownRAT | GUI | N/A | Storage access, Custom Android deployment tools (photo snap, screenshot), Audio recording. |
| WH-RAT | GUI Panel | • wh-Cyberspace/WH-RAT | Leaked variant structurally tied to SpyNote/NjRAT architectures. (Detailed telemetry payloads under expansion). |
| Xenomorph / GODFather / PixPirate / Sova / Zanubis / BingoMod / TrickMo / BlankBot / Vultur / Octo2 / Medusa | Advanced Banking Trojans | N/A (Active Threat Campaigns) | Complete Device Takeover (ATS / Accessibility Services Abuse), Persistent Device Administrator escalation, External/Internal storage traversal, Direct automated ADB framework execution, Complete text tracking (SMS, Web notification mirroring), Installed app enumeration, Real-time automated injection templates (Phishing/Overlays), Bypasses standard biometric/PIN locks. |
| ZeroDayRAT | Stealer Vector | N/A | Real-time SMS interception, Call routing details extraction, Active input keylogger module, Camera deployment, Microphone environment scraping, Baseband device profiles enumeration, Cryptographic wallet asset stealer. |
This repository is an updated, restructured, and actively maintained evolution of the original project by wishihab
- Active Maintenance: Tracking modern Android threats up to Android SDK 36 (OneUI 8.5+).
- Enhanced Scannability: Restructured from loose bulleted lists into high-density Markdown directories.
- Telemetry Data: Integrating deeper structural permissions, capability matrices, and architectural markers.
Because this is a completely overhauled and expanded version of the database, your contributions are vital to keeping it accurate!
Whether you want to add a modern malware strain, patch an incorrect permission metric, or fix a broken upstream link:
- Fork this repository.
- Create your branch (
git checkout -b patch/Add-New-RAT). - Follow our updated high-density data matrix layout.
- Submit a Pull Request targeting our master branch.
Warning
This directory is published entirely for informational, educational, and defensive malware research purposes.
The maintainers of both the original repository and this evolved fork DO NOT condone, encourage, or support the deployment of Remote Access Trojans (RATs), spyware, or any unauthorized surveillance tools.
Under NO circumstances shall the current or past maintainers of this information be held liable for any misuse, device damage, or legal consequences resulting from the deployment, execution, or modification of the software documented in this directory.
