Skip to content
Ritusmin Saikia edited this page Nov 7, 2025 · 1 revision

Welcome to the PhantomRAT wiki!

PhantomRAT-V2 — Research Overview (Ethical Use Only)

Purpose

PhantomRAT-V2 is a remote administration and monitoring research project focused on Android security. It exists for educational and penetration testing purposes only, within the boundaries of law and explicit consent.

This document provides a non-actionable, safe, and ethical overview of the repository, emphasizing responsible use, structure, security risks, and best practices for legitimate research.


⚠️ Legal and Ethical Notice

  • Unauthorized access or control of devices is illegal in most jurisdictions.
  • Use only on systems you own or have written permission to test.
  • Always operate within a defined legal scope, such as:
    • Signed penetration testing contracts.
    • Academic research with institutional approval.
    • Isolated lab experiments on test devices.

Any use outside these contexts may violate privacy and computer misuse laws.


Repository Structure (High-Level)

File / Folder Description (non-actionable)
rat.py Client orchestrator module for proof-of-concept.
server.py Command controller logic (research artifact).
builder.py Build script (do not use for deployment).
config.py Placeholder for configuration variables.
utils.py, shell.py, banner.py Utility and interface helpers.
Compiled_APK/, Payloads/ Binary artifacts (handle securely).
assets/, base/, Jar_utils/, Logs/, Dumps/ Support and output folders.
install_gradle_oneclick.sh Gradle setup script (lab use only).

Sensitive files or compiled binaries should never be shared or executed on unauthorized systems.


Declared Features (Descriptive Only)

The repository includes descriptions of remote-administration features typically seen in security-testing frameworks. This documentation lists them for awareness, not use.

  • Accessibility permission control (auto-grant simulation)
  • Device info collection (for telemetry research)
  • SMS, call log, and contacts enumeration
  • Location and network state retrieval
  • Media capture (photo, video, audio)
  • Screen capture and file management
  • Keylogging (accessibility-based)
  • Shell interaction
  • Icon hiding and persistence experiments

Security note:
These features can expose personal data. Use strictly for research, not surveillance or exploitation.


Safe Testing Environment

Operate only in a closed lab setup.

Recommended Practices

  • Use offline networks or VLANs with no internet access.
  • Run on virtual machines or physical test devices only.
  • Label and isolate all test data and artifacts.
  • Use disposable test accounts.
  • Securely delete logs and payloads after testing.
  • Keep written authorization from the system owner.

Never connect real user devices or credentials.


Security Risk Summary

PhantomRAT-V2 contains functionality that can be abused if misused.
This section summarizes major risks and how to mitigate them.

High-Risk Areas

  • Accessibility automation and keylogging.
  • Remote shell execution.
  • Media capture (camera, mic, screen).
  • Embedded configuration files and credentials.

Review Priorities

  • Remove or disable sensitive features before distribution.
  • Sanitize binaries, logs, and dumps.
  • Check that no hardcoded IPs, URLs, or API keys exist.
  • Document intended research boundaries clearly in the repository.

Hardening and Defensive Guidance

  • Follow Principle of Least Privilege: restrict permissions.
  • Disable or comment out high-risk modules before public release.
  • Use dummy servers and sandboxed C2 simulations.
  • Add runtime checks to prevent use outside test conditions.
  • Never log credentials, messages, or identifiers.
  • Strip binaries and purge compiled payloads before uploading to GitHub.
  • Provide clear ethical statements in the README.

Create a “safe build” variant that disables sensitive capabilities for demonstration purposes.


Responsible Use Checklist

Before running or sharing:

  1. Have written permission from device/system owner.
  2. Use isolated lab or virtual environment.
  3. Strip sensitive code and binaries.
  4. Keep test logs encrypted or private.
  5. Do not distribute compiled payloads.
  6. Document purpose and authorization scope.

If any condition is unmet, do not run or share.


Responsible Vulnerability Disclosure

If vulnerabilities or unsafe behaviors are found:

  1. Report privately to the repository owner (email or GitHub security contact).
  2. Avoid sharing exploit details publicly.
  3. Allow reasonable remediation time.
  4. Use anonymized logs and safe reproductions.
  5. Notify affected vendors if relevant.

Following coordinated disclosure protects researchers and users alike.


Contributor Guidelines and Ethics

Contributions should focus on:

  • Defensive research.
  • Security auditing tools.
  • Documentation or safety improvements.

Avoid contributions that add or strengthen offensive capability.

Contributor checklist:

  • Does your change increase potential misuse?
  • Have you removed any secrets or binaries?
  • Have you documented safe testing practices?

Ethical contributions protect the project and its legitimacy.


Contact and License

  • Provide a contact email for private reports or collaboration.
  • Review the repository’s LICENSE file for compliance.
  • Add a clear disclaimer such as:

“This project is for authorized security research and education only.
The author(s) are not responsible for misuse or damage.”

If you intend to share research, comply with export and cyber laws in your country.


Audit & Review Template (Optional)

Researchers can use this basic checklist to evaluate safety before publication.

Audit Area Reviewer Notes
Code contains no hardcoded credentials
No direct internet-exposed endpoints
All binaries stripped or removed
README includes ethical disclaimer
Safe testing environment documented
Contributor guidelines updated

Summary

PhantomRAT-V2 is a security research framework, not a consumer or attack product.
This documentation is designed to:

  • Encourage lawful, transparent testing.
  • Prevent misuse by clarifying legal limits.
  • Support ethical academic and cybersecurity research.

Operate within strict consent boundaries and follow responsible disclosure at all times.


End of Wiki