Repository navigation
Home
Welcome to the PhantomRAT wiki!
PhantomRAT-V2 is a remote administration and monitoring research project focused on Android security. It exists for educational and penetration testing purposes only, within the boundaries of law and explicit consent.
This document provides a non-actionable, safe, and ethical overview of the repository, emphasizing responsible use, structure, security risks, and best practices for legitimate research.
- Unauthorized access or control of devices is illegal in most jurisdictions.
- Use only on systems you own or have written permission to test.
- Always operate within a defined legal scope, such as:
- Signed penetration testing contracts.
- Academic research with institutional approval.
- Isolated lab experiments on test devices.
Any use outside these contexts may violate privacy and computer misuse laws.
| File / Folder | Description (non-actionable) |
|---|---|
rat.py |
Client orchestrator module for proof-of-concept. |
server.py |
Command controller logic (research artifact). |
builder.py |
Build script (do not use for deployment). |
config.py |
Placeholder for configuration variables. |
utils.py, shell.py, banner.py
|
Utility and interface helpers. |
Compiled_APK/, Payloads/
|
Binary artifacts (handle securely). |
assets/, base/, Jar_utils/, Logs/, Dumps/
|
Support and output folders. |
install_gradle_oneclick.sh |
Gradle setup script (lab use only). |
Sensitive files or compiled binaries should never be shared or executed on unauthorized systems.
The repository includes descriptions of remote-administration features typically seen in security-testing frameworks. This documentation lists them for awareness, not use.
- Accessibility permission control (auto-grant simulation)
- Device info collection (for telemetry research)
- SMS, call log, and contacts enumeration
- Location and network state retrieval
- Media capture (photo, video, audio)
- Screen capture and file management
- Keylogging (accessibility-based)
- Shell interaction
- Icon hiding and persistence experiments
Security note:
These features can expose personal data. Use strictly for research, not surveillance or exploitation.
Operate only in a closed lab setup.
Recommended Practices
- Use offline networks or VLANs with no internet access.
- Run on virtual machines or physical test devices only.
- Label and isolate all test data and artifacts.
- Use disposable test accounts.
- Securely delete logs and payloads after testing.
- Keep written authorization from the system owner.
Never connect real user devices or credentials.
PhantomRAT-V2 contains functionality that can be abused if misused.
This section summarizes major risks and how to mitigate them.
- Accessibility automation and keylogging.
- Remote shell execution.
- Media capture (camera, mic, screen).
- Embedded configuration files and credentials.
- Remove or disable sensitive features before distribution.
- Sanitize binaries, logs, and dumps.
- Check that no hardcoded IPs, URLs, or API keys exist.
- Document intended research boundaries clearly in the repository.
- Follow Principle of Least Privilege: restrict permissions.
- Disable or comment out high-risk modules before public release.
- Use dummy servers and sandboxed C2 simulations.
- Add runtime checks to prevent use outside test conditions.
- Never log credentials, messages, or identifiers.
- Strip binaries and purge compiled payloads before uploading to GitHub.
- Provide clear ethical statements in the README.
Create a “safe build” variant that disables sensitive capabilities for demonstration purposes.
Before running or sharing:
- Have written permission from device/system owner.
- Use isolated lab or virtual environment.
- Strip sensitive code and binaries.
- Keep test logs encrypted or private.
- Do not distribute compiled payloads.
- Document purpose and authorization scope.
If any condition is unmet, do not run or share.
If vulnerabilities or unsafe behaviors are found:
- Report privately to the repository owner (email or GitHub security contact).
- Avoid sharing exploit details publicly.
- Allow reasonable remediation time.
- Use anonymized logs and safe reproductions.
- Notify affected vendors if relevant.
Following coordinated disclosure protects researchers and users alike.
Contributions should focus on:
- Defensive research.
- Security auditing tools.
- Documentation or safety improvements.
Avoid contributions that add or strengthen offensive capability.
Contributor checklist:
- Does your change increase potential misuse?
- Have you removed any secrets or binaries?
- Have you documented safe testing practices?
Ethical contributions protect the project and its legitimacy.
- Provide a contact email for private reports or collaboration.
- Review the repository’s LICENSE file for compliance.
- Add a clear disclaimer such as:
“This project is for authorized security research and education only.
The author(s) are not responsible for misuse or damage.”
If you intend to share research, comply with export and cyber laws in your country.
Researchers can use this basic checklist to evaluate safety before publication.
| Audit Area | Reviewer Notes |
|---|---|
| Code contains no hardcoded credentials | |
| No direct internet-exposed endpoints | |
| All binaries stripped or removed | |
| README includes ethical disclaimer | |
| Safe testing environment documented | |
| Contributor guidelines updated |
PhantomRAT-V2 is a security research framework, not a consumer or attack product.
This documentation is designed to:
- Encourage lawful, transparent testing.
- Prevent misuse by clarifying legal limits.
- Support ethical academic and cybersecurity research.
Operate within strict consent boundaries and follow responsible disclosure at all times.
End of Wiki