Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-05 13:27:31 UTC Home > List all groups > List all tools > List all groups using tool MMRat Tool: MMRat Names MMRat Category Malware Type Banking trojan, Backdoor, Info stealer, Credential stealer Description (Trend Micro) The Trend Micro Mobile Application Reputation Service (MARS) team discovered a new, fully undetected Android banking trojan, dubbed MMRat (detected by TrendMicro as AndroidOS_MMRat.HRX), that has been targeting mobile users in Southeast Asia since late June 2023. The malware, named after its distinctive package name com.mm.user, can capture user input and screen content, and can also remotely control victim devices through various techniques, enabling its operators to carry out bank fraud on the victim’s device. Furthermore, MMRat uses a special customized command-and-control (C&C) protocol based on protocol buffers (aka Protobuf), an open-source data format used for serializing structured data. This feature, which is rarely seen in Android banking trojans, enhances its performance during the transfer of large volumes of data. Information Last change to this tool card: 13 October 2023 Download this tool card in JSON format All groups using tool MMRat Changed Name Country Observed Unknown groups   _[ Interesting malware not linked to an actor yet ]_   https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=cddf5428-abee-4308-8ab6-ac5bb744e312 Page 1 of 2 1 group listed (0 APT, 0 other, 1 unknown) Source: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=cddf5428-abee-4308-8ab6-ac5bb744e312 https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=cddf5428-abee-4308-8ab6-ac5bb744e312 Page 2 of 2