HeroRat Android RAT
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Affected platforms
The following platforms are known to be affected:
Threat details
Threat actors distribute HeroRat via social engineering on third-party app stores, social media and instant messaging. Users are lured into downloading the app by promises including free bitcoins and free followers.
When the app is installed, it prompts the user to grant permissions which can include granting administrator access to the device. It then displays a message saying that the app can't run on the device and will be uninstalled. The app's icon is removed but HeroRat continues to run automatically in the background and registers a new infected device with the threat actor.
HeroRat uses the Telegram messaging protocol for Command and Control signalling. It can steal information from text messages and contacts, send text messages, make calls, record the screen and audio, find the device's location and alter device settings.
Hundreds of variants have been observed in this malware family since the source code was leaked in March 2018.
Remediation advice
To prevent and detect a trojan infection, ensure that:Remediation steps
| Type | Step |
|---|---|
|
Last edited: 17 February 2020 12:44 pm