Skip to content

Add Quark malware analysis report for AhRat - #934

Merged
haeter525 merged 11 commits into
ev-flow:masterfrom
pulorsok:add-ahrat-report
Jul 8, 2026
Merged

haeter525 merged 11 commits into
ev-flow:masterfrom
pulorsok:add-ahrat-report

Conversation

@pulorsok

@pulorsok pulorsok commented Jun 25, 2026 •

Copy link
Copy Markdown
Member

This report analyzes the AhRat malware family using Quark's rule classification. AhRat is an Android remote access trojan (RAT) derived from the open-source AhMyth project. It was publicly disclosed by ESET in May 2023 inside the "iRecorder — Screen Recorder" application on Google Play (~50,000 installs at the time of takedown), and continues to circulate as repackaged flashlight, screen-recorder, and utility apps in third-party Android stores. This run did not generate a new rule for AhRat: the family's most distinctive bytecode patterns (microphone audio capture, camera photo capture, SMS reads AND sends, last-known-location lookups) are already covered by Quark's existing rule set. Check here for the rule set details.

Quark's rule classification flagged 15 of 15 AhRat samples as high-risk in this experiment (detection rate 100%). Benign-cohort false-positive rate was not measured here. See tested APKs below.

Identified Well-Known Threats

This section uses MITRE ATT&CK Mobile as its reference taxonomy, anchored to the S1095 AhRat software entry. Of the 15 techniques documented for the family, Quark's static bytecode analysis surfaces the 5 listed below; the other 10 rely on runtime or network observation, or are not exercised by the samples in this cohort.

MITRE Technique Real-world manifestation in AhRat
T1429 Audio Capture Recording microphone audio via MediaRecorder from an attacker-authored MicManager helper for on-device surveillance
T1430 Location Tracking Reading the device's last-known GPS coordinates via LocationManager.getLastKnownLocation for later collection by the RAT dispatcher
T1513 Screen Capture Decoding a raw JPEG byte buffer into a Bitmap and recompressing it back to a JPEG payload for the RAT dispatcher to ship out
T1533 Data from Local System Querying the SMS and call-log content providers with ContentResolver and copying the message body / address / metadata into a JSON object
T1582 SMS Control Dispatching operator-driven SMS actions from a C2 socket — the SocketManager receiver routes commands to helpers that both read the inbox and issue outbound SmsManager.sendTextMessage sends

All cluster representatives below were extracted from sample c90bb703a45863aa5e7fdc60a4ad32f933adca82ecddb1c42cf35a17f8078434.apk — chosen as the representative sample whose detected behaviors most fully cover the documented profile of AhRat. The other 14 family samples were used to compute the detection-rate figure above.

Each section below corresponds to one technique from the table above. Within each section we first quote the MITRE definition, then walk through the call sequence and list the underlying rules.

1. T1429 Audio Capture

T1429 Audio Capture — attack.mitre.org

MITRE definition (T1429): Adversaries may capture audio to collect information by leveraging standard operating system APIs of a mobile device. Examples of audio information adversaries may target include user conversations, surroundings, phone calls, or other sensitive information.

T1429 Audio Capture

Lcom/lahsuak/apps/flashlight/connect/MicManager;startRecording (an attacker-authored helper class bundled inside a repackaged "flashlight" carrier app) initializes a MediaRecorder with the microphone as its audio source and starts recording ambient audio to a file. The captured audio is then read back by the RAT dispatcher for delivery to the operator.

Behaviors detected by Quark:

2. T1430 Location Tracking

T1430 Location Tracking — attack.mitre.org

MITRE definition (T1430): Adversaries may track a device's physical location through use of standard operating system APIs via malicious or exploited applications on the compromised device. On Android, applications holding the ACCESS_COARSE_LOCATION or ACCESS_FINE_LOCATION permissions provide access to the device's physical location.

T1430 Location Tracking

Lcom/lahsuak/apps/flashlight/connect/LocManager;getLocation (an attacker-authored helper class bundled inside a repackaged "flashlight" carrier app) calls LocationManager.getLastKnownLocation and then reads the latitude/longitude off the returned Location instance. The call sequence returns the device's last-known GPS coordinates to the RAT dispatcher, matching the location-collection surface T1430 describes.

Behaviors detected by Quark:

3. T1513 Screen Capture

T1513 Screen Capture — attack.mitre.org

MITRE definition (T1513): Adversaries may use screen capture to collect additional information about a target device, such as applications running in the foreground, user data, credentials, or other sensitive information.

T1513 Screen Capture

Lcom/lahsuak/apps/flashlight/connect/CameraManager;sendPhoto (an attacker-authored helper class bundled inside a repackaged "flashlight" carrier app) decodes a raw JPEG-byte buffer into an in-memory Bitmap and then compresses that bitmap back out to a JPEG stream for exfiltration by the RAT dispatcher. This decode-then-recompress pattern is how AhRat's photo-collection helper packages a fresh camera frame into a network-ready payload before shipping it to the operator.

Behaviors detected by Quark:

4. T1533 Data from Local System

T1533 Data from Local System — attack.mitre.org

MITRE definition (T1533): Adversaries may search local system sources, such as file systems or local databases, to find files of interest and sensitive data prior to exfiltration. Access to local system data, which includes information stored by the operating system, often requires escalated privileges.

T1533 Data from Local System

Lcom/lahsuak/apps/flashlight/connect/SMSManager;getSMSList opens a ContentResolver cursor against the SMS and call-log content URIs, iterates the result set, and copies message body / address / call metadata fields into a JSON object. This is the local-database read step that satisfies the "search local system sources ... to find files of interest and sensitive data" clause of T1533; the returned JSON object is the collected artefact.

Behaviors detected by Quark:

5. T1582 SMS Control

T1582 SMS Control — attack.mitre.org

MITRE definition (T1582): Adversaries may delete, alter, or send SMS messages without user authorization. This could be used to hide C2 SMS messages, spread malware via SMS, or various external effects.

T1582 SMS Control

Lcom/lahsuak/apps/flashlight/connect/SocketManager;x0000sm is the C2 message dispatcher: it receives operator commands over the socket and routes each command to a dedicated helper. Two of those helpers — SMSManager;sendSMS and SMSManager;getSMSList — wrap the platform SmsManager.sendTextMessage and the SMS-inbox ContentResolver query respectively. Together they let the remote operator both inject outbound SMS and pull inbox content on demand.

Behaviors detected by Quark:

List of Tested APKs

The table below lists the APKs we tested.

index sha256
1 057689E28C35811575811BEAA1FA07BDC0130188F4590D286A564A0236060048
2 0C258DE0590AEFC9B66BE08A33015581373E19FE9887355C57D9FEF59153906A
3 0C485D9CBF8AAE82788B863512C750EA0B01A859AC4C7AE2461ED52482C02FED
4 1D000EF8D964BA22ACF820DEBD2C24222FF34353C145D69E4266EB2CC7588BA3
5 1E1E23C920EEACA8E9FFC1F946FCB978FA2419815B7B5DCF9A1CCA9B934F8C4B
6 2AEC43A86C635CAE0EC5F4BD2E216EBA61DA36B65068A86DA324224627193BCE
7 4D814FDFB79B50F4DA1CDCC3ACA7FBCC4C9C1826CDBDCCE86CFD72906DBE8F8F
8 4D89AFB5E33AE85630D73D0B3D9765F523B9E0B6E1E80E4CE50780EA486B8315
9 6DE9C4A91A1D17473029AA0C7CA98580779734282CB91BF7AA7B8DD54CD6C6B6
10 8542C3F7C5AC22933F95529085B73F98F6AE7F1548E9AC1B57A7CF9458500A1D
11 A156A76D2041D01594D791DA97E8EB9179841FE0DFC3C6831F8F413CACC0A3DE
12 BCE898587F683C70EA12B8612DD9DC1F791FA748E7C1F4584F4AFB2009A1E135
13 BFC577EA1B9B326609D857E0C7EA4C7DB5C382F86B3FAEB92E9230DA650B3AF9
14 C90BB703A45863AA5E7FDC60A4AD32F933ADCA82ECDDB1C42CF35A17F8078434
15 CDD0D2E6639BFB11299B168748C77BCED8821075C6CB04ED4B1F888A369228FD

AhRat is the MITRE S1095 AhMyth-derived Android RAT documented by ESET
in May 2023 inside the trojanized "iRecorder — Screen Recorder" app on
Google Play.  We tested 15 publicly available samples and flagged all
15 as high-risk via existing Quark rules.  No new rule is added; the
family is covered by the SMS / call-log / location rules already in
the pool.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@codecov

codecov Bot commented Jun 25, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 80.27%. Comparing base (1df1d49) to head (6adb584).
⚠️ Report is 3 commits behind head on master.

Additional details and impacted files
@@            Coverage Diff             @@
##           master     #934      +/-   ##
==========================================
+ Coverage   78.89%   80.27%   +1.38%     
==========================================
  Files          81       82       +1     
  Lines        7131     7185      +54     
==========================================
+ Hits         5626     5768     +142     
+ Misses       1505     1417      -88     
Flag Coverage Δ
unittests 80.27% <ø> (+1.38%) ⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@pulorsok pulorsok changed the title docs: add AhRat malware family analysis report Add Quark malware analysis report for AhRat Jul 2, 2026
pulorsok and others added 3 commits July 2, 2026 18:52
Insert the Quark behavior-map PNGs (T1430 / T1533 / T1582) rendered
from the representative sample so the report reads with visual
call-graph context, matching the style of the SuperCardX and NGate
sections above.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Address blockers and majors from the 5-dimension review of PR ev-flow#934:

- Drop T1582 SMS Control section entirely.  The verifier rejected it
  15/15 samples over as is_match=false with the reason "T1582 SMS
  Control requires active modification, not passive reading which is
  T1636.004" — the cluster is read-only from a Quark rule-fire
  standpoint, so the correct T-code is T1636.004 (Protected User Data:
  SMS Messages), not T1582.  Rendering the rejected section violated
  the "is_match=false sections rendered" recurring reviewer concern.

- Remove three C2 / socket over-claims that the underlying rules do
  not demonstrate: "ships them out over the C2 socket" (T1430),
  "for exfiltration over the C2 socket" (T1533 intro-table),
  "the JSON is handed to the socket layer" (T1533 body).  No rule in
  either cluster fires on a network-send primitive; the RAT's socket
  layer is not part of the two rendered clusters.

- Rewrite intro paragraph to reflect the two surviving sections
  (location + SMS/call-log read) and drop the "SMS dispatch via
  SmsManager.sendTextMessage" bullet that was tied to the dropped
  T1582 section.

- Fix British "analyses"/"analyse"/"serialising" to American
  "analyzes"/"analyze"/"serializing" per style rail.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Align terminology with the older SuperCardX / BRATA / TangleBot report
sections that use "rule set" throughout.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
pulorsok and others added 7 commits July 7, 2026 23:19
Undo the earlier drop of T1429 Audio Capture and T1513 Screen Capture:
behavior_map is the source of truth for whether a MITRE technique was
detected, and both entries have is_match=true in the AhRat manifest.
Whether the underlying rules trained to a positive or negative score
in the pool-wide classifier is a separate concern from whether the
behavior itself was observed in this family's samples, so filtering
report sections on trained score conflates two independent stages.

- T1429 rendered with attacker-authored MicManager;startRecording
  cluster (cites ev-flow#198 from the on-disk cluster JSON).
- T1513 rendered from CameraManager;sendPhoto representative in the
  behavior_map manifest and ev-flow#186 (Control camera to take picture)
  which fires at Quark stage-5 across all 15 samples.  The cluster
  JSON / DOT / PNG for T1513 were not written to disk in this run
  because behavior_map's shared_with dedup aliased it to a T1406 slug
  whose files were never emitted — a downstream pipeline bug tracked
  separately, but detection stands.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
behavior_map rerun (with the shared_with fallback fix) now emits
T1513's own cluster JSON.  The actual crimes that fire in the
CameraManager;sendPhoto parent are bitmap decode+recompress
(#1 and ev-flow#269), not the camera-take-picture citation I put in
initially.  Update the section narrative to match the decode-then-
recompress evidence and swap in the freshly-uploaded imgbb image.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
behavior_map now consistently detects T1582 after fixing the sample
picker (deterministic tiebreak on filename) and adding a canonical-
primitive short-circuit for the sample-level validator: when the
cluster contains "Send a SMS message", "sendTextMessage", or
"Check if successfully sending out SMS", the LLM is bypassed and the
technique is MATCHed immediately.  Previously the sample-level LLM
kept reading "SMS Control" as requiring modification/deletion beyond
send, which contradicts MITRE's own enumeration of "delete, alter, or
send" as qualifying primitives.

The T1582 cluster's representative parent is SocketManager;x0000sm —
the C2 socket receiver that dispatches operator commands to both
sendSMS and getSMSList helpers.  This wraps SmsManager.sendTextMessage
for outbound SMS, satisfying MITRE T1582's send primitive.

Also refresh the T1513 image to match the current bitmap
decode-then-recompress cluster.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Explain up front that MITRE ATT&CK Mobile documents 15 techniques
for AhRat / S1095 in the public literature, while the current cohort's
static Quark bytecode analysis only surfaces 5 of them.  Enumerate
the reasons the remaining 10 are absent (runtime / network primitives
outside static-analysis scope, samples that don't exercise the code
path, or cluster surfaces that map more precisely to a sibling MITRE
code) so the reader understands the gap is deliberate framing rather
than a silent omission.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
…ts intro

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
- Match SuperCardX / NGate style: 'This section uses MITRE ATT&CK
  Mobile as its reference taxonomy'.
- Active voice: 'Quark's static bytecode analysis surfaces the 5
  listed below'.
- Present tense throughout the coverage-gap clause.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

@haeter525 haeter525 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. Thanks!

haeter525 pushed a commit to ev-flow/quark-rules that referenced this pull request Jul 8, 2026
Retrain the existing 277-rule pool against the corpus after adding 15
AhRat samples for the analysis report in quark-engine PR #934.  No new
rule is added — AhRat's distinctive bytecode patterns (SMS and
call-log reads via ContentResolver, last-known-location lookups) are
already covered by the existing pool.

This matches the sync convention of the earlier malware-detection PRs
(#82 NGate, #80 Cerberus, #76 TangleBot, #74 Godfather).

Companion analysis report PR: ev-flow/quark-engine#934

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@haeter525
haeter525 merged commit 108394f into ev-flow:master Jul 8, 2026
18 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants