AngelRAT & Onimai RAT – Android Remote Access Trojans Explained

Blacksec

Administrator
Staff member
You know the puppet trick — the puppeteer behind the curtain, one hand up the puppet, making it wave and dance while the audience watches the puppet, not the curtain. An Android RAT is the same thing, minus the theater: the puppeteer is a stranger, the puppet is a phone, and the audience is nobody because the whole show happens in the victim's pocket.

People search angelrat and onimai rat a few hundred times a month — usually because they heard a name in a Telegram group, or saw a screenshot of a panel controlling a phone. The names change, the RATs change, but the story never changes: how they work, how they get in, and why the "free cracked builder" you're about to download is the most dangerous app in the room. Let's walk through it properly.

RAT 101: What These Things Actually Are​


A Remote Access Trojan (RAT) is a program that secretly installs on a device and gives its owner remote control over it. On Android, that control is built from a stack of permissions and Android APIs — each one innocent alone, terrifying in combination:

  • Accessibility Service – the crown jewel. This is the permission designed for screen readers and auto-clickers; a RAT with it can read everything on screen, click buttons for the victim, and even swipe away system warnings. Every serious Android RAT is built around it.
  • Overlay drawing – the RAT can paint fake screens on top of real apps. That's how banking logins get phished mid-session: a real-looking login page drawn over the real app, capturing what the victim types.
  • Camera, microphone, location – live spying, remote-triggered. Some RATs even flash the screen briefly to mask that the camera is on.
  • SMS and call access – reading messages (including 2FA codes), logging calls, even recording them.
  • Keylogging – everything typed, from passwords to searches.
  • App management – installing more apps, hiding icons, uninstalling security tools, locking the device (ransomware mode).

Add "invisible icon" and "survives reboots" and you've got the standard feature list of AngelRAT, Onimai, and the whole family. The specifics of each builder differ — panel design, payload size, price — but the anatomy is the same: permissions, accessibility, overlays, remote control.

AngelRAT and Onimai RAT: The Family Tree​


Let's be honest about names: AngelRAT and Onimai RAT are not single products — they're a lineage of Android RAT builders that share code, panels, and marketing across Telegram channels. RATs fork constantly; a builder appears, gets cracked, forks into three new names, and the cycle repeats. That's why you'll see the same features under different names and the same names with different versions. Understanding the family matters more than memorizing the members:

  • AngelRAT – a newer Android RAT with the modern feature set (accessibility-based, overlay phishing, remote camera). Sold via Telegram, marketed to the same crowd that buys "free accounts" and card tools.
  • Onimai RAT – similar builder lineage, popular because of aggressive free/leaked builds floating around — which, per the universal law of this ecosystem, are the most dangerous ones to touch.
  • EagleSpy – an older, very well-known Android RAT, frequently "cracked" and repackaged. Same family, longer criminal record.
  • Craxs RAT – the most famous current one; the full mechanics are in our Craxs guide. These articles are siblings: if you understand one Android RAT's anatomy, you understand all of them.

The pattern worth internalizing: the names are marketing, the anatomy is shared. Learn the anatomy and no rebranding will ever confuse you again.

How a RAT Gets Onto a Phone (the five doors)​


No RAT teleports. Every infection walks through one of these doors, and the doors are all psychological:

  1. The tempting APK. A "cracked game," a "premium mod," a "free movie app" — shared in a chat or a forum. The victim sideloads it (Play Protect disabled because the "game" demands it), grants the permissions, and the installer owns the phone from that moment on.
  2. The verification page. "This video needs an app to play" / "Verify your age" — downloads an APK. One tap, done.
  3. The fake update. "Update your app to continue" — on a fake page that looks like the Play Store. The APK is the RAT wearing the app's name.
  4. The "cracked RAT builder" itself. The meta-door: someone downloads a "free cracked" RAT builder to attack others — and the builder is a RAT. The hunter becomes the hunted. This is the most common story in this entire ecosystem, and it's worth a section of its own.
  5. The physical touch. Someone with a minute of access to an unlocked phone installs a "system update" APK. Rare, but it's why lock screens exist.

Every door has the same lock: permission. The victim installs and grants. RATs are guests — they can only enter when invited. That's not blame; it's the single fact that makes defense possible.

The Accessibility Permission: Why the Whole Battle Is One Dialog​


If you remember one technical detail, make it this: on modern Android, a RAT without Accessibility access is a blind man with a flashlight, and a RAT with it is a puppeteer. The Accessibility Service permission is what lets the RAT read screens, simulate taps, and bypass the "this app can draw over others" warnings. That's why every infection flow is engineered around one moment: getting the victim to grant Accessibility.

The scripts are all the same shape — "tap Settings, then Accessibility, then enable this app" — usually wrapped in a fake reason: "needed for the game to run," "needed for the mod to apply," "needed to fix the video player." The moment that toggle flips, the RAT is armed. This is why the defensive advice is so repetitive it sounds boring: never grant Accessibility to an app you didn't install from a real store, and audit it monthly. Boring advice, because the boring detail is the whole war.

The Cracked-Builder Trap (read this twice)​


Here's the specific nightmare that deserves its own section, because it's the most common way people in this scene get burned: you download a "free cracked" AngelRAT or Onimai builder from a Telegram channel or a "leaks" forum. It even works — you bind an APK, you control a test phone. Great demo. And quietly, the cracked builder is doing its own thing:

  • It's a RAT itself. The "builder" you installed is a trojan. The moment you run it, your own device — PC or Android — is the victim, and the person who "cracked" it is watching your banking apps, your sessions, your camera.
  • It harvests your data. Even if the builder is a "clean" repack, the cracker commonly adds credential theft, clipboard logging, and session hijacking. Your Telegram session, your cards, your account passwords — all shipped home.
  • It reports your targets. Every APK you bind with the cracked builder gets a backdoor for the cracker — your "victim" is also their victim, and the panel logs you too.
  • It's the law enforcement honeypot. Some "free builders" are operated by security researchers and LE tracking the exact population who downloads them. The download itself becomes a data point in a file.

The sentence to tattoo somewhere: if the RAT builder is free, you're the target. The real builders are sold for money precisely because their buyers are customers, not victims. The "cracked free" copies are the product being sold — and the buyer is the product.

How to Detect a RAT on an Android Phone​


For anyone reading this with a suspicious phone — yours or someone's who asked you to check — here's the practical sweep:

  1. Check Accessibility immediately. Settings → Accessibility. Every enabled service should be one you installed and remember. Anything unknown: turn it off, then uninstall the app behind it.
  2. Audit installed apps. Look for apps you didn't install, generic names, blank icons, or apps with no Play Store page. Sort by "recently installed" — RATs arrive recently.
  3. Watch battery and data. A RAT recording screen, audio, and camera eats power and bandwidth. A phone that dies by afternoon and burns GBs on a hidden app is a phone with a guest.
  4. Look for the camera/mic indicator. Android shows a dot when camera or mic is active. If it lights up when you're not using them, something else is.
  5. Check the notification access list. Settings → Apps → Special access → Notification access. RATs love reading notifications for 2FA codes.
  6. Play Protect scan. It catches many common payloads — run it from the Play Store settings.
  7. If it persists: safe mode, then factory reset. Safe mode (hold power, long-press "Power off") stops third-party apps; uninstall the suspect there. If you can't find it, back up photos and reset — the reset is the certainty.

After any infection: change passwords from a clean device, log out all sessions, and check banking and email for anything odd. Assume everything typed on the infected phone was read.

Prevention (the boring, working list)​


  • Sideload nothing from chats. Play Store or the vendor's official site, full stop.
  • Never disable Play Protect for an install. If an app demands it, the app is the demand.
  • Never grant Accessibility to anything you didn't install knowingly from a real source.
  • Keep Android updated — RAT infection paths lean on old vulnerabilities when they exist.
  • Don't download "cracked" builders of anything. The crack is the con, always, everywhere.

FAQ​


What is AngelRAT?​


AngelRAT is an Android remote access trojan builder sold through Telegram channels, with the standard RAT feature set: accessibility-based control, overlay phishing, remote camera/mic, keylogging, SMS access, and app management. Like most Android RATs it's a rebranded fork of an older lineage, and the "free cracked" copies circulating are overwhelmingly backdoored — the download is the trap.

Is the Onimai RAT real or fake?​


Onimai is a real Android RAT builder in the same family — real code, real panels, circulating free/leaked builds. "Real" doesn't mean safe: the leaked builds are the most dangerous versions, because they commonly carry their own hidden payload for the downloader. The RAT is real; the free copy is the scam.

Can antivirus detect Android RATs like AngelRAT?​


Sometimes. Play Protect and Android AV apps catch many common signatures, but builders re-pack payloads constantly to change signatures, so detection is never guaranteed. The reliable defense is behavioral: audit Accessibility, notification access, installed apps, and data usage. The checklist in this guide beats any scanner.

How do I remove an Android RAT?​


Safe mode, revoke Accessibility and Notification access, uninstall the unknown app, run a Play Protect scan, and if anything remains, factory reset after backing up photos. Then change all passwords from a clean device and log out every session. The reset is the only 100% step — use it when in doubt.

Can an Android RAT survive a factory reset?​


In virtually all consumer cases, no — a reset wipes the app and its persistence. The rare exceptions involve firmware-level infections, which are far beyond typical RAT builders. If you're dealing with one of those, treat the phone as compromised hardware and dispose of it properly.

Final Thoughts​


Strip the names and the marketing, and every Android RAT is the same puppet show: a permission-granted guest with a remote hand. The defense is the mirror of the attack — don't sideload, don't grant Accessibility, don't trust free cracked anything, and audit the two permission lists when your gut says check. The people who get burned in this scene aren't the ones who met a clever RAT; they're the ones who downloaded the "free" one. The names change next month. The anatomy doesn't. Learn the anatomy.

Related: Craxs RAT — the same anatomy, the most famous name · Keyloggers, on the PC side of the family

— The BlackSec Guides Team

Discussion thread: blacksec.net/forums/ — detection logs and permission-hygiene tips welcome.
 
Top