A new Android spyware named “RatMilad” has been discovered targeting mobile devices in the Middle East, used to spy on victims and steal data.
The RatMilad spyware was discovered by mobile security firm Zimperium, which warned that the malware could be used for cyber espionage, blackmail, or to monitor a victim's conversations.
See also: Cheerscrypt ransomware linked to Emperor Dragonfly hacking group

Distributed via fake Android apps
The spyware is distributed via a fake virtual number generator used to activate social media accounts called “NumRent.” Once installed, the application requests too many permissions and then abuses them to load the malicious RatMilad payload.

The main distribution channel for the fake app is Telegram, as the NumRent app or other trojans carrying RatMilad are not available on the Google Play Store or third-party stores.
See also: Optus data breach: 2.1 million customers' ID numbers exposed
RatMilad threat actors have also created a dedicated website to promote the mobile remote access trojan (RAT) to make the application appear more convincing. This website is promoted via URLs shared on Telegram or other social media and communication platforms.

After successfully installing on a victim's device, RatMilad hides behind a VPN connection and attempts to steal the following data:
- Basic device information (model, brand, buildID, Android version)
- Device MAC address
- Contact list
- Written messages
- Call logs
- Account names and permissions
- List of installed applications and permissions
- Clipboard data
- GPS location data
- SIM information (number, country, IMEI, status)
- File list
- File contents
Additionally, RatMilad can perform file actions, such as deleting files and stealing files, modifying the permissions of the installed application, or even using the device's microphone to record audio and eavesdrop on a conversation in the room.

These capabilities are more than enough to collect corporate information, personal data, private communications, photos, videos, documents, etc.
Zimperium discovered RatMilad after the spyware failed to load on a customer's device and proceeded to analyze the malware.
From the evidence, Zimperium concludes that RatMilad operators are taking a random target approach rather than executing a laser-focused campaign.
See also: Water Labbu group breaks into other hackers' crypto scam sites and "steals money"
At the time of the investigation, the Telegram channel used to distribute the spyware was viewed over 4,700 times and counted over 200 external shares.
To protect yourself from Android spyware infections like this, always avoid downloading apps outside of the Google Play Store and carefully check the permissions requested during installation.
Information source: bleepingcomputer.com
