Usually any Android Device can be hacked using Metasploit Meterpreter attack but many people are not aware of that process as it is not user friendly. But using a simple tool called AndroRAT (Android Remote Administration Tool) it is possible for anyone to hack any Android device. By successfully running this tool one can retrieve following information from target Android device.

  • Get contacts (and all theirs informations)
  • Do vibrate the phone
  • Get call logs
  • Open an URL in the default browser
  • Get all messages
  • Send a text message
  • Location by GPS/Network
  • Do a toast
  • Monitoring received messages in live
  • Streaming video (for activity based client only)
  • Monitoring phone state in live (call received, call sent, call missed..)
  • Stream sound from microphone (or other sources..)
  • Take a picture from the camera

You can do almost anything with this tool. All you need to do is to install a simple application on target Android device. This application is generated by AndroRAT tool which further can be binded(joined) with any android application for stealth(Anonymity). Once you have installed the deploy package(.apk) on Android device you can control the device anonymously through a user-friendly GUI.

Things you'll need: 

  1. AndroRAT (Android Remote Administration Tool), Which can be downloaded from here.(Turn off Anti-virus, this zip file is not virus but the anti-virus shows it as virus because it is a Hacking Software).

  2. Router Port Forwarder (Only if you are using a wireless router), download from here.
  3. An Android device to test the deploy package.
  4. A good internet connection.
  5. Basic computer knowledge.
  6. A bit of patience.

Prerequisites(for wireless router users):

  1. Download the Router Port Forwarder tool from the above link.
  2. Install it on you PC and open it.
  3. The software automatically detects your router model number and displays it.
  4. Now in the "Port forwarding" tab click "Add".
  5. In the next window enter the name of the port as you like, leave the protocol as tcp, enter the port you would like to open (Ex. 8080,1234,4444...).
  6. And finally the internal ip address.
  7. To know your internal IP address open Start > Run, and then enter ncpa.cpl, this opens active network connections.(you must be connected to the internet)
  8. Right click on the connected network and click status and then click details.
  9. In the details windows check the Ipv4 address, it should be something like 192.168.XX.XX.
  10. Note the Ip address for further use. This is your internal ip address.
Note: You should check your internal ip only when you are connected to the internet.

Procedure to create a deploy package:

  1. Download the AndroRAT Zip and extract it.
  2. Download any Android application like Temple run, Subway Surfers with which you would like to bind the hacking application.
  3. Open the extracted folder and then run the application AndroRat Binder.
  4. It should look like the below screenshot.
  5. Now in the Ip box enter your internal ip address which you have noted in the prerequisites.(If you don't know your ip address read prerequisites from step 7.)
  6. In the second box enter the port which you have opened in port forwarder tool (only wireless router users, other can enter the port whatever they like).
  7. In the third box, browse and select the target application with which you would like to bind the hacking application.
  8. Now hit 'Go' and wait for the AndroRat to build the deploy apk.
  9. Once the process completes you will find the result application in the same AndroRat folder.
  10. Now Install it one any Android device and open it.(Note that the device should have an active internet connection)

 Steps to control the Target Android Device:

  1. Once you have successfully installed the result apk that was generated by AndroRat, you can control the victim's Android device through a well designed GUI.
  2. In the AndroRat folder, again open the AndroRat folder.
  3. In that folder you will find a java application named "AndroRat".
  4. When you open it for the first time, allow the firewall exception for the application.
  5. Now click server at the top and enter the port which you have opened before.
  6. Save it and restart the application. Now the application starts listening to the new port.
  7. In this application you will find the list of connected devices.
  8. Double click the device you would like to access and you see a window with full built-in controls.
  9. Note that the target device is listed as long as he is connected to the internet and is using the deploy application created by AndroRat.

Note: 
  1. If the application does not work and no devices are listed in the AndroRat application, try building just the Hacking application instead of binding it other application.
  2. For the users who are using wireless routers, port forwarding is a must.
  3. Before trying it on others devices try it on your own Android first.
  4. Turn off the Anti-virus before extracting the AndroRat zip which you have downloaded.
  5. If possible turn off Firewall too.
  6. Make sure you have a Good internet connection.
  7. Happy Hacking!!
Disclaimer: Controlling others Android Mobile without their permission is illegal. This post is for educational purpose only and never try to misuse it. To prevent these kind of hacks, make sure you read all the app permissions before you install any application.

For Developers: You can get the source code from here.

0 comments:

Post a Comment

 
Top