Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Malware

RadzaRat

RadzaRat is an Android remote access trojan (RAT) / spyware family discovered by Certo Software and publicly reported in late 2025. It is described as an Android MaaS tool first made public on November 8, 2025, and is disguised as a legitimate file manager application, including lures presenting it as a utility for handling photos and documents. Reporting states it was sold on underground forums by a developer using the name Heron44, with low-cost infrastructure based on services such as Render.com and Telegram, lowering the barrier to deployment.

Documented capabilities include full remote control of infected Android devices, remote file-system access, browsing and downloading files from the victim device, support for file transfers up to 10 GB, keystroke logging, and extensive surveillance functionality. The malware uses Telegram for command-and-control. It achieves persistence through Android boot-related permissions including RECEIVE_BOOT_COMPLETED, is configured to restart after device reboot, requests that battery optimizations be ignored, and uses aggressive methods to resist being closed by Android.

The malware is associated with credential and financial-data theft risk, including capture of passwords and credit card numbers via keylogging. It targets Android devices and has been observed impersonating a file manager utility rather than a sector-specific business application. At the time of reporting, Certo Software stated the APK installer was openly accessible online and that VirusTotal showed a 0/66 detection rate, indicating no major antivirus detections at that time.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

MITRE ATT&CK

Techniques & procedures

6 distinct techniques documented for this family, organized by ATT&CK tactic.

Persistence

1 technique
T1547Boot or Logon Autostart ExecutionEvidence1

The program... also uses aggressive methods to stop Android from closing it and ensures it restarts automatically every time the device reboots.

Privilege Escalation

1 technique
T1547Boot or Logon Autostart ExecutionEvidence1

The program... also uses aggressive methods to stop Android from closing it and ensures it restarts automatically every time the device reboots.

Stealth

1 technique
T1036MasqueradingEvidence1

RadzaRat is hidden within an application that appears to be a normal file manager, a tool used to handle photos and documents.

Credential Access

1 technique
T1056.001KeyloggingEvidence2

Once installed, it grants criminals extensive access, allowing them to browse and download files with advertised support for transfers up to 10 gigabytes, and even track everything you type, a feature known as keylogging.

Collection

1 technique
T1056.001KeyloggingEvidence2

Once installed, it grants criminals extensive access, allowing them to browse and download files with advertised support for transfers up to 10 gigabytes, and even track everything you type, a feature known as keylogging.

Command and Control

2 techniques
T1071Application Layer ProtocolEvidence1

This capability is clearly demonstrated in the image shared by Certo Software researchers, which shows the malware operating and logging keystrokes via Telegram.

T1105Ingress Tool TransferEvidence1

Once installed, it grants criminals extensive access, allowing them to browse and download files with advertised support for transfers up to 10 gigabytes.

Other

1 technique
T1562Impair DefensesEvidence1

The program... also uses aggressive methods to stop Android from closing it...

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping6

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.