WolfRAT is malware based on a leaked version of Dendroid that has primarily targeted Thai users. WolfRAT has most likely been operated by the now defunct organization Wolf Research.[1]
WolfRAT can receive system notifications.[1]
WolfRAT can record call audio.[1]
WolfRAT can collect user account, photos, browser history, and arbitrary files.[1]
WolfRAT can update the running malware.[1]
WolfRAT can delete files from the device.[1]
WolfRAT has masqueraded as "Google service", "GooglePlay", and "Flash update".[1]
WolfRAT’s code is obfuscated.[1]
WolfRAT uses dumpsys to determine if certain applications are running.[1]
dumpsys
WolfRAT can collect the device’s call log.[1]
WolfRAT can collect the device’s contact list.[1]
WolfRAT can collect SMS messages.[1]
WolfRAT can record the screen and take screenshots to capture messages from Line, Facebook Messenger, and WhatsApp.[1]
WolfRAT can delete and send SMS messages.[1]
WolfRAT can obtain a list of installed applications.[1]
WolfRAT sends the device’s IMEI with each exfiltration request.[1]
WolfRAT can take photos and videos.[1]
WolfRAT can perform primitive emulation checks.[1]