Add Quark malware analysis report for AhRat - #934
Merged
Merged
Conversation
AhRat is the MITRE S1095 AhMyth-derived Android RAT documented by ESET in May 2023 inside the trojanized "iRecorder — Screen Recorder" app on Google Play. We tested 15 publicly available samples and flagged all 15 as high-risk via existing Quark rules. No new rule is added; the family is covered by the SMS / call-log / location rules already in the pool. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## master #934 +/- ##
==========================================
+ Coverage 78.89% 80.27% +1.38%
==========================================
Files 81 82 +1
Lines 7131 7185 +54
==========================================
+ Hits 5626 5768 +142
+ Misses 1505 1417 -88
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
Insert the Quark behavior-map PNGs (T1430 / T1533 / T1582) rendered from the representative sample so the report reads with visual call-graph context, matching the style of the SuperCardX and NGate sections above. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Address blockers and majors from the 5-dimension review of PR ev-flow#934: - Drop T1582 SMS Control section entirely. The verifier rejected it 15/15 samples over as is_match=false with the reason "T1582 SMS Control requires active modification, not passive reading which is T1636.004" — the cluster is read-only from a Quark rule-fire standpoint, so the correct T-code is T1636.004 (Protected User Data: SMS Messages), not T1582. Rendering the rejected section violated the "is_match=false sections rendered" recurring reviewer concern. - Remove three C2 / socket over-claims that the underlying rules do not demonstrate: "ships them out over the C2 socket" (T1430), "for exfiltration over the C2 socket" (T1533 intro-table), "the JSON is handed to the socket layer" (T1533 body). No rule in either cluster fires on a network-send primitive; the RAT's socket layer is not part of the two rendered clusters. - Rewrite intro paragraph to reflect the two surviving sections (location + SMS/call-log read) and drop the "SMS dispatch via SmsManager.sendTextMessage" bullet that was tied to the dropped T1582 section. - Fix British "analyses"/"analyse"/"serialising" to American "analyzes"/"analyze"/"serializing" per style rail. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Align terminology with the older SuperCardX / BRATA / TangleBot report sections that use "rule set" throughout. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Undo the earlier drop of T1429 Audio Capture and T1513 Screen Capture: behavior_map is the source of truth for whether a MITRE technique was detected, and both entries have is_match=true in the AhRat manifest. Whether the underlying rules trained to a positive or negative score in the pool-wide classifier is a separate concern from whether the behavior itself was observed in this family's samples, so filtering report sections on trained score conflates two independent stages. - T1429 rendered with attacker-authored MicManager;startRecording cluster (cites ev-flow#198 from the on-disk cluster JSON). - T1513 rendered from CameraManager;sendPhoto representative in the behavior_map manifest and ev-flow#186 (Control camera to take picture) which fires at Quark stage-5 across all 15 samples. The cluster JSON / DOT / PNG for T1513 were not written to disk in this run because behavior_map's shared_with dedup aliased it to a T1406 slug whose files were never emitted — a downstream pipeline bug tracked separately, but detection stands. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
behavior_map rerun (with the shared_with fallback fix) now emits T1513's own cluster JSON. The actual crimes that fire in the CameraManager;sendPhoto parent are bitmap decode+recompress (#1 and ev-flow#269), not the camera-take-picture citation I put in initially. Update the section narrative to match the decode-then- recompress evidence and swap in the freshly-uploaded imgbb image. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
behavior_map now consistently detects T1582 after fixing the sample picker (deterministic tiebreak on filename) and adding a canonical- primitive short-circuit for the sample-level validator: when the cluster contains "Send a SMS message", "sendTextMessage", or "Check if successfully sending out SMS", the LLM is bypassed and the technique is MATCHed immediately. Previously the sample-level LLM kept reading "SMS Control" as requiring modification/deletion beyond send, which contradicts MITRE's own enumeration of "delete, alter, or send" as qualifying primitives. The T1582 cluster's representative parent is SocketManager;x0000sm — the C2 socket receiver that dispatches operator commands to both sendSMS and getSMSList helpers. This wraps SmsManager.sendTextMessage for outbound SMS, satisfying MITRE T1582's send primitive. Also refresh the T1513 image to match the current bitmap decode-then-recompress cluster. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Explain up front that MITRE ATT&CK Mobile documents 15 techniques for AhRat / S1095 in the public literature, while the current cohort's static Quark bytecode analysis only surfaces 5 of them. Enumerate the reasons the remaining 10 are absent (runtime / network primitives outside static-analysis scope, samples that don't exercise the code path, or cluster surfaces that map more precisely to a sibling MITRE code) so the reader understands the gap is deliberate framing rather than a silent omission. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
…ts intro Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
- Match SuperCardX / NGate style: 'This section uses MITRE ATT&CK Mobile as its reference taxonomy'. - Active voice: 'Quark's static bytecode analysis surfaces the 5 listed below'. - Present tense throughout the coverage-gap clause. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
haeter525
pushed a commit
to ev-flow/quark-rules
that referenced
this pull request
Jul 8, 2026
Retrain the existing 277-rule pool against the corpus after adding 15 AhRat samples for the analysis report in quark-engine PR #934. No new rule is added — AhRat's distinctive bytecode patterns (SMS and call-log reads via ContentResolver, last-known-location lookups) are already covered by the existing pool. This matches the sync convention of the earlier malware-detection PRs (#82 NGate, #80 Cerberus, #76 TangleBot, #74 Godfather). Companion analysis report PR: ev-flow/quark-engine#934 Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This was referenced Aug 3, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This report analyzes the AhRat malware family using Quark's rule classification. AhRat is an Android remote access trojan (RAT) derived from the open-source AhMyth project. It was publicly disclosed by ESET in May 2023 inside the "iRecorder — Screen Recorder" application on Google Play (~50,000 installs at the time of takedown), and continues to circulate as repackaged flashlight, screen-recorder, and utility apps in third-party Android stores. This run did not generate a new rule for AhRat: the family's most distinctive bytecode patterns (microphone audio capture, camera photo capture, SMS reads AND sends, last-known-location lookups) are already covered by Quark's existing rule set. Check here for the rule set details.
Quark's rule classification flagged 15 of 15 AhRat samples as high-risk in this experiment (detection rate 100%). Benign-cohort false-positive rate was not measured here. See tested APKs below.
Identified Well-Known Threats
This section uses MITRE ATT&CK Mobile as its reference taxonomy, anchored to the S1095 AhRat software entry. Of the 15 techniques documented for the family, Quark's static bytecode analysis surfaces the 5 listed below; the other 10 rely on runtime or network observation, or are not exercised by the samples in this cohort.
MediaRecorderfrom an attacker-authoredMicManagerhelper for on-device surveillanceLocationManager.getLastKnownLocationfor later collection by the RAT dispatcherBitmapand recompressing it back to a JPEG payload for the RAT dispatcher to ship outContentResolverand copying the message body / address / metadata into a JSON objectSocketManagerreceiver routes commands to helpers that both read the inbox and issue outboundSmsManager.sendTextMessagesendsAll cluster representatives below were extracted from sample
c90bb703a45863aa5e7fdc60a4ad32f933adca82ecddb1c42cf35a17f8078434.apk— chosen as the representative sample whose detected behaviors most fully cover the documented profile of AhRat. The other 14 family samples were used to compute the detection-rate figure above.Each section below corresponds to one technique from the table above. Within each section we first quote the MITRE definition, then walk through the call sequence and list the underlying rules.
1. T1429 Audio Capture
T1429 Audio Capture — attack.mitre.org
Lcom/lahsuak/apps/flashlight/connect/MicManager;startRecording(an attacker-authored helper class bundled inside a repackaged "flashlight" carrier app) initializes aMediaRecorderwith the microphone as its audio source and starts recording ambient audio to a file. The captured audio is then read back by the RAT dispatcher for delivery to the operator.Behaviors detected by Quark:
2. T1430 Location Tracking
T1430 Location Tracking — attack.mitre.org
Lcom/lahsuak/apps/flashlight/connect/LocManager;getLocation(an attacker-authored helper class bundled inside a repackaged "flashlight" carrier app) callsLocationManager.getLastKnownLocationand then reads the latitude/longitude off the returnedLocationinstance. The call sequence returns the device's last-known GPS coordinates to the RAT dispatcher, matching the location-collection surface T1430 describes.Behaviors detected by Quark:
3. T1513 Screen Capture
T1513 Screen Capture — attack.mitre.org
Lcom/lahsuak/apps/flashlight/connect/CameraManager;sendPhoto(an attacker-authored helper class bundled inside a repackaged "flashlight" carrier app) decodes a raw JPEG-byte buffer into an in-memoryBitmapand then compresses that bitmap back out to a JPEG stream for exfiltration by the RAT dispatcher. This decode-then-recompress pattern is how AhRat's photo-collection helper packages a fresh camera frame into a network-ready payload before shipping it to the operator.Behaviors detected by Quark:
4. T1533 Data from Local System
T1533 Data from Local System — attack.mitre.org
Lcom/lahsuak/apps/flashlight/connect/SMSManager;getSMSListopens aContentResolvercursor against the SMS and call-log content URIs, iterates the result set, and copies message body / address / call metadata fields into a JSON object. This is the local-database read step that satisfies the "search local system sources ... to find files of interest and sensitive data" clause of T1533; the returned JSON object is the collected artefact.Behaviors detected by Quark:
5. T1582 SMS Control
T1582 SMS Control — attack.mitre.org
Lcom/lahsuak/apps/flashlight/connect/SocketManager;x0000smis the C2 message dispatcher: it receives operator commands over the socket and routes each command to a dedicated helper. Two of those helpers —SMSManager;sendSMSandSMSManager;getSMSList— wrap the platformSmsManager.sendTextMessageand the SMS-inboxContentResolverquery respectively. Together they let the remote operator both inject outbound SMS and pull inbox content on demand.Behaviors detected by Quark:
List of Tested APKs
The table below lists the APKs we tested.