In the digital world, what’s useful today can become harmful tomorrow. Unfortunately, this is precisely what happened with iRecorder – Screen Recorder. This screen-recording Android application with over 50,000 installs was launched in September 2021 as a legitimate app. However, the app now contains a new Android remote access Trojan (RAT) based on AhMyth. This open-source remote administration tool can be used to access informational data from an Android device, cybersecurity vendor ESET found on May 23, 2023. The RAT, which ESET researchers called AhRat, can exfiltrate files with specific extensions and microphone recordings and upload them to the attacker’s command and control (C2) server. The malicious code was likely added when the app was updated to version 1.3.8, made available in August 2022. The ESET researchers noted that while malicious Android apps are legion, adding malicious code to a legitimate app is much more uncommon. “The application’s specific malicious behavior potentially indicates its involvement in an espionage campaign,” the research report reads. AhMyth has been used by Transparent Tribe, also known as APT36, a cyber espionage group known for its extensive use of social engineering techniques and targeting of government and military organizations in South Asia. “Nevertheless, we cannot
Read More











