Skip to main content

HeroRat Android RAT

HeroRat is a remote access trojan (RAT) that targets Android devices and has been sold to threat actors on the Telegram messaging app since August 2017.
Report a cyber attack: call 0300 303 5222 or email [email protected]

This content has been archived

This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk

Summary

HeroRat is a remote access trojan (RAT) that targets Android devices and has been sold to threat actors on the Telegram messaging app since August 2017.

Affected platforms

The following platforms are known to be affected:

Threat details

Threat actors distribute HeroRat via social engineering on third-party app stores, social media and instant messaging. Users are lured into downloading the app by promises including free bitcoins and free followers.

When the app is installed, it prompts the user to grant permissions which can include granting administrator access to the device. It then displays a message saying that the app can't run on the device and will be uninstalled. The app's icon is removed but HeroRat continues to run automatically in the background and registers a new infected device with the threat actor.

HeroRat uses the Telegram messaging protocol for Command and Control signalling. It can steal information from text messages and contacts, send text messages, make calls, record the screen and audio, find the device's location and alter device settings.

Hundreds of variants have been observed in this malware family since the source code was leaked in March 2018.


Remediation advice

To prevent and detect a trojan infection, ensure that:

Remediation steps

Type Step
  • Apps can only be installed from authorised and trusted sources such as official stores.
  • Apps are only granted necessary permissions.
  • A robust program of education and awareness training is delivered to users to ensure they don’t open attachments or follow links within unsolicited messages.
  • Network, proxy and firewall logs should be monitored for suspicious activity.
  • Your organisation adopts a holistic all-round approach to Cyber Security as advocated by the 10 Steps to Cyber Security.

Last edited: 17 February 2020 12:44 pm