We Smell A RatMilad Android Spyware
ID: e00584f3-d166-5206-be0a-61da8503d705
STIX ID: report--e00584f3-d166-5206-be0a-61da8503d705
Feed Name: Zimperium Blog
Threat Score
**Executive summary:** Zimperium zLabs discovered and analyzed RatMilad, an Android Remote Access Trojan/spyware distributed via sideloaded fake apps (Text Me / NumRent) promoted on Telegram; the malware harvests SMS, contacts, call logs, files, microphone/camera recordings, GPS and device identifiers, communicates with C2 servers using defined jobIDs, and includes multiple IoCs (package names, domains, SHA‑256 hashes) with guidance for detection and mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
