Skip to main content

ViperRAT Remote Access Trojan

ViperRAT is an Android-based remote access trojan. First observed in 2016 being used by an Iranian advanced persistent threat group to target the Israeli Defence Force, it has now resurfaced on the Google Play Store.
Report a cyber attack: call 0300 303 5222 or email [email protected]

This content has been archived

This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk

Summary

ViperRAT is an Android-based remote access trojan. First observed in 2016 being used by an Iranian advanced persistent threat group to target the Israeli Defence Force, it has now resurfaced on the Google Play Store.

Affected platforms

The following platforms are known to be affected:

Threat details

Originally distributed through dating apps using social engineering, ViperRAT is now disguised as a number of instant messaging applications. Once installed it will ask the user for full permissions before hiding itself and contacting a command and control server.

ViperRAT will attempt to collect a wide variety of information including contact lists, device configuration and audio recordings. It can also initiate phone calls and turn on the screen.


Remediation steps

Type Step
  • Users should only download applications from trusted sources and only when they are required. If possible, organisations should maintain allow lists of approved applications.
  • Robust education should be provided to users to ensure they are aware of the threat posed by malicious mobile applications.

Last edited: 23 June 2020 9:31 pm