Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors AppMilad

Description

AppMilad is an Iranian hacking group that has been identified as the source of a spyware campaign called RatMilad. This spyware is designed to silently infiltrate victims' devices and gather personal and corporate information, including private communications and photos. The group has been distributing the spyware through fake apps and targeting primarily Middle Eastern enterprises.

AI Analysis

· 1 week ago

Executive Summary

AppMilad is an Iranian hacking group known for the RatMilad spyware campaign. They target primarily Middle Eastern enterprises through fake apps, aiming to gather corporate and personal information.

Goals & Targeting

AppMilad's goals appear to be centered around the acquisition of sensitive corporate information and personal data. By targeting Middle Eastern enterprises, they may be seeking to gather intelligence relevant to political or economic interests, possibly aligned with broader Iranian espionage objectives. Their choice of fake apps as a delivery mechanism indicates an understanding of target demographics and a desire for stealthy infiltration.

Enhanced Description

AppMilad is an Iranian threat group identified as the source of the RatMilad spyware. This malware infiltrates devices covertly, targeting corporate and personal data, including communications and photos. The group's primary method involves distributing malicious software through fake apps, particularly focusing on Middle Eastern enterprises. Their activities suggest a focus on intelligence gathering, likely for espionage purposes, with an emphasis on sectors that could provide strategic or economic advantages.

Key Capabilities

  • Developing custom spyware (RatMilad)
  • Distribution via fake applications
  • Data exfiltration capabilities
  • Persistent backdoor creation
  • Surveillance toolkit implementation

MITRE ATT&CK Tactics

Espionage
Surveillance
Network investigation discovery

ATT&CK Techniques

T1055
T1003.001
T1059

Software / Tooling

RatMilad spyware
Fake apps (likely custom built)

Campaigns & Victims

AppMilad has been observed targeting Middle Eastern businesses over several years. Their campaigns typically involve initial infection through app distribution, followed by lateral movement within networks and data exfiltration. No specific high-profile campaigns have been widely reported beyond their use of RatMilad spyware.

IOC Patterns

  • Spear-phishing emails with fake app download links
  • Malicious app distribution via compromised or legitimate-looking stores
  • C2 communication over HTTPS (potential anomalies)
  • Registry entries or file patterns indicative of malware persistence

Recommended Actions

  • Implement rigorous application vetting processes for enterprise devices.
  • Monitor network traffic for unusual outbound communications, especially from internal systems.
  • Educate users on the risks of downloading applications from unverified sources.
  • Conduct regular endpoint detection and response (EDR) checks for signs of RatMilad infection indicators.
  • Develop an incident response plan tailored to potential spyware incidents.

Suggested Tags

APT
Cyber Espionage
Middle East Targeting
Corporate Espionage
Fake App Distribution

Confidence Assessment

Confidence is medium in the accuracy of the threat actor's details due to limited available intelligence. Further clarity would help confirm specific TTPs, associated tools beyond RatMilad, and exact campaign history.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Financial Targeting
APT
Cyber Espionage
Middle East Targeting
Corporate Espionage
Fake App Distribution

Details

Type
Unknown
Country of Origin
I
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.