CapraRAT: what it is and how to remove it

CapraRAT is a Remote Access Trojan that has recently surfaced in the wild, mainly targeting Indian users. It is believed that it is a modified version of previously known malware AndroRAT, as numerous similarities have been found between the two.

Facts checked October 6, 2026. Removal steps tested on Windows 11 (26H2) and checked against Microsoft's and the browser makers' current documentation. Sections marked as our earlier report are the original text: they describe the threat as it was then and have not been reviewed since. The 2026 status, the removal steps and the questions are current.

Automatic

Get a free scan and check if your PC is infected.

Fortect finds malware, unwanted programs and the Windows damage they leave behind, and repairs it in one pass.

An automatic scan checks installed programs, startup items and browser extensions for anything that came with CapraRAT.

Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free.

Do it yourself · free Remove CapraRAT yourself 3 steps, about 9 minutes, no software needed.

Start the steps
Screenshot of CapraRAT: virus
CapraRAT as our 2022 report showed it.

CapraRAT: summary

NameCapraRAT
TypeMalware, data-stealer
Name in deviceAndroid Services
Cybercriminal groupAPT36
PurposeSteals various personal information from the phone, including contacts, SMS, and more
Detection namesNo Microsoft detection name is known
Removal

Scan the PC with security software to find and remove the malware and anything installed with it. Fortect scans Windows for malware and repairs the system files and settings it damaged.

Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free.
Show 6 more facts
DistributionNot recorded in the old report
DamageNot recorded in the old report
SymptomsAn unknown program in Installed apps
Evidence4 write-ups by security sites; details still limited
First seen28 September 2022
Facts checked6 October 2026

What CapraRAT does

From our report of Sep 2022 · not reviewed since

Obfuscation and capabilities

It is important to note that, once the CapraRAT virus is installed, it may omit not visible symptoms, or at least they may be extremely difficult to notice if they are not specifically looked into. In this case, there are quite a few tricks that malware uses to make it seem like there's nothing out of the ordinary happening on the device.

For example, the main application name on the device is shown as "Android Services," which many people wouldn't find unusual. The package name, which represents the installer, is named "com.example.appcode.appcode," which usually would also not spark any suspicions. Whenever the malicious app is running, it would use the "Android Services" name of the app and completely hide its original icon from the user.

At all times, whenever CapraRAT is operational (this means whenever users have their phones turned on), it would constantly communicate with a remote Command & Control server, which is used by the attackers for communication between the malicious app and them.

This allows cybercriminals to send all sorts of commands to the device, including:

These are just a few commands that could be sent by the attackers - the app can also access and delete files, modify the dialing number, send SMS messages on behalf of the user, access call logs, and more.

The Trojan makes it a perfect spying device, and, considering that malware is targeting governmental institution personnel, it is not hard to see how much damage it could cause by conducting international espionage.

  • "READ_CONTACTS" allows access to all phone contacts;
  • "READ_SMS" allows access to all SMS on the victim's phone;
  • "ACCESS_FINE_LOCATION" allows access to the precise location of the user;
  • "RECORD_AUDIO" allows to record everything that is being said via the phone's microphone;
  • "RECEIVE_SMS" allows intercepting all SMS received on the device, etc.

From our report of Sep 2022 · not reviewed since

More from our earlier report on CapraRAT

  • Perform a full device scan with security software
  • To make sure that all leftover and junk files are eliminated, use

What CapraRAT collects and where it sends it

From our report of Sep 2022 · not reviewed since

CapraRAT is a Remote Access Trojan that has recently surfaced in the wild, mainly targeting Indian users.

It is believed that it is a modified version of previously known malware AndroRAT, as numerous similarities have been found between the two.

Developers of the virus, known as APT36 from Pakistan, have been previously found distributing fake versions of the Aarogya Setu application, which is the official app for Covid tracking in India. The main target of the attack seems to be personnel of the Indian Government and the exfoliation of personal data from the devices.

Screenshot of CapraRAT: virus
CapraRAT in our 2022 report.

How CapraRAT got on your PC

From our report of Sep 2022 · not reviewed since

Currently, there are over 2.6 million apps on Google Play Store, and it remains the largest distributor of apps out there.

Google's security scanners always check the apps that are being uploaded, but cybercriminals may sometimes find loopholes in its defense systems, which results in malware slipping through. Nevertheless, these instances are extremely rare, and it remains the safest platform for Android users.

Despite this, users still access third-party websites to download apps. Usually, they either want an app that may be illegal, or they are tricked by a phishing link sent to them via SMS, Facebook Messenger, or other means.

That is precisely how CapraRAT is spread, and if you have downloaded apps in this way, it is important you check your device thoroughly as soon as possible - it may be infected with a Remote Access trojan or other malware. Keeping your Android patched with the latest security updates is just as important, as malware can exploit vulnerabilities otherwise.

Note that Android devices would not allow installations of third-party apps by default, although this security measure can be turned off. Do not disable security measures implemented by developers, as they are there for a reason. You would always get a warning about an app possibly being insecure.

How to remove CapraRAT

How to remove CapraRAT and secure your accounts

A stealer usually takes what it wants within minutes and may already be gone.

The scan comes first, then the accounts.

  1. Step 1: Scan the PC, then run the offline scan

    Open Windows Security > Virus & threat protection > Scan options, run a Full scan and remove everything it finds. Then select Microsoft Defender Antivirus (offline scan) and click Scan now: the PC restarts and scans before Windows loads, which finds files that hide while Windows runs.

    Save your work first, because the offline scan takes about 15 minutes. Both scans are built into Windows 11 and Windows 10, and a second scanner from another vendor is a useful extra opinion.

    Windows Security Scan options with Microsoft Defender Antivirus offline scan selected
    Windows 11: Windows Security > Virus & threat protection > Scan options.

    Full procedure with screenshots: Run a Microsoft Defender Offline scan

  2. Step 2: Change passwords from another device and sign out other sessions

    Assume that the passwords saved in this PC's browsers, and the accounts that were open in them, are known to the attacker. From a phone or a clean computer, change the e-mail password first, then banking, shopping, social and gaming accounts.

    Use each service's option to sign out of all other sessions, because stolen cookies keep a session open even after a password change. Turn on two-step verification on each account. Wait with the infected Windows 11 or Windows 10 PC until the scans are clean.

    Full procedure with screenshots: Turn on two-step verification / secure a hacked account

  3. Step 3: Delete the folders left behind

    What the uninstaller leaves behind is usually in the user folders. Open File Explorer, switch on View > Show > Hidden items (in Windows 10 View > Hidden items), and go through %LocalAppData%, %AppData%, %ProgramData% and the two Program Files folders.

    Sort by Date modified and delete folders that appeared together with the problem and belong to no program you use. Folders with random names that hold .exe, .dll, .js or .ps1 files are the strongest sign.

    Full procedure with screenshots: Remove what malware leaves behind in Windows

Access your website securely from any location

When you work on the domain, site, blog, or different project that requires constant management, content creation, or coding, you may need to connect to the server and content management service more often. The best solution for creating a tighter network could be a dedicated/fixed IP address.

If you make your IP address static and set to your device, you can connect to the CMS from any location and do not create any additional issues for the server or network manager that needs to monitor connections and activities. VPN software providers like can help you with such settings and offer the option to control the online reputation and manage projects easily from any part of the world.

Recover files after data-affecting malware attacks

While much of the data can be accidentally deleted due to various reasons, malware is one of the main culprits that can cause loss of pictures, documents, videos, and other important files.

More serious malware infections lead to significant data loss when your documents, system files, and images get encrypted. In particular, ransomware is is a type of malware that focuses on such functions, so your files become useless without an ability to access them.

Even though there is little to no possibility to recover after file-locking threats, some applications have features for data recovery in the system. In some cases, can also help to recover at least some portion of your data after data-locking virus infection or general cyber infection.

From our report of Sep 2022 · not reviewed since

CapraRAT removal

The implications of having a Remote Access Trojan installed on a device that is used by government representatives can be severe and pose a threat to the national security of India. The detection and removal of CapraRAT are crucial for that not to happen, and the best way to ensure this is by employing reputable security software, such as or , and never ignoring any of the warnings it produces.

Using security software, you can remove malware from your device. Alternatively, you could try to eliminate the app yourself:

Before proceeding, make sure you take out your SIM card from the phone

Clear Storage and data files on Android from Google Chrome or other apps:

The process varies depending on the model of your phone, so please refer to the manufacturer's official website.

  • Go to Settings -> Apps/Applications.
  • Expand the full list of the installed apps.
  • Scroll through the list and tap on a suspicious application once.
  • Tap on it and select Uninstall.
  • Reboot the device.
  • Go to Settings > Apps/Applications.
  • Expand the full list of the installed apps.
  • Tap on Chrome and select Storage & cache.
  • Clear storage and clear cache of the app.

Questions about CapraRAT

Is CapraRAT a virus?

Most programs that appear the way CapraRAT did are not viruses in the strict sense. They are potentially unwanted programs:

  • real software that arrives bundled with other downloads and then shows offers
  • changes browser settings
  • starts with Windows

Some are harmless, some are annoying and a few carry adware. What makes it worth removing is that you did not choose it.

Uninstall it from Installed apps and check the startup list and the browsers for anything added the same day. If it refuses to uninstall or returns after a restart, treat it as more serious and run a Microsoft Defender offline scan.

How do I stop programs like CapraRAT from being installed again?

Most unwanted programs arrive through installers, so the fix is in how you install software. Download programs from their official sites or the Microsoft Store, not from download portals or ads above search results. During setup, choose Custom or Advanced installation and untick every extra offer, including browsers, toolbars and optimizers.

Decline update prompts that appear inside other programs unless you know them. In Windows Security, turn on reputation-based protection and potentially unwanted app blocking. These steps would most likely have stopped CapraRAT before it reached the app list.

What happens to the stolen data?

Stolen data is packed into "logs", one per infected PC. The criminal who ran the stealer uses them directly or sells them in online markets, where others search them for bank, crypto, e-mail, gaming and business accounts.

This can happen days or months after the infection. That is why changing passwords and ending sessions matters even if nothing has happened yet. Breach notification services such as Have I Been Pwned can tell you when your e-mail address appears in known leaks.

How can someone log in without my two-step code?

By using a session instead of a login. When you sign in, the site gives the browser a cookie that says you already passed both steps. Spyware like CapraRAT copies that cookie, and the attacker loads it into their own browser, so the site sees a logged-in user and asks for nothing.

The fix is to end all sessions in the account's security settings, which makes the copied cookie worthless, and then change the password. Some services also show active sessions with locations, which helps spot misuse.

Is CapraRAT still on my computer?

Possibly, possibly not. Some stealers stay and keep collecting; others delete themselves after one run. The sign you saw, capraRAT in the list of installed apps, only shows that data was used, not where the program is now.

A Microsoft Defender offline scan answers the first question; checking Startup apps, Task Scheduler and the Downloads folder for files from the days before helps too. Either way, the account steps are needed, because stolen passwords and cookies keep working after the program is gone, sometimes for weeks.

Is CapraRAT a known stealer?

Not as a named family yet. The sign, capraRAT in the list of installed apps, is typical of information stealers, keyloggers or clippers, but no analysis links CapraRAT to a specific one. That is common:

  • victims notice the effects
  • such as lost accounts or swapped addresses
  • before anyone sees the file

You do not need the family name to act. Change passwords from a clean device, sign out of all sessions, move crypto to a new wallet and run a Microsoft Defender offline scan on the PC. If a scan gives a detection name, note it for the report.

Should I stop using this PC?

Only for sensitive things, and only until it is clean. Do not log in to banking, e-mail or crypto on it until the offline scan finds nothing. You can keep using it to follow the removal steps.

If the scans keep finding new items, or protection keeps switching off, back up your documents and reset Windows. After that the PC is as safe as a new one, but the accounts still need the steps in this guide, because a reset cannot undo data that was already sent.

Should I report CapraRAT to the police?

Yes, if money was lost or accounts were misused. A police report gives you a reference number that banks, exchanges and insurers often ask for. Include when you first saw capraRAT in the list of installed apps, the accounts and amounts involved, any wallet addresses or messages, and what you downloaded before it started.

In the US, use the FBI's IC3; in the UK, Report Fraud; in other countries, the national police cybercrime unit. Reporting rarely brings money back quickly, but it helps link cases and is often required for refunds.

Should I report a stealer infection?

Report it if money was taken, accounts were used for fraud, or your identity was misused. The report gives you a reference number for your bank and helps police link cases. Also tell the services involved:

  • banks
  • PayPal
  • crypto exchanges and e-mail providers have their own fraud teams that can freeze transfers
  • restore accounts

An infection with no misuse yet does not need a police report, but acting on your accounts does. Keep the antivirus log that shows CapraRAT; it helps explain the case.

Will Fortect remove CapraRAT?

Fortect scans Windows for malware and unwanted programs and repairs the system files and settings they change, and its free scan shows what it finds on your PC before you decide anything.

For CapraRAT, follow the plan above as well: the browser steps take back permissions and settings that no scanner treats as a threat, and uninstalling the program that brought it removes the source.

Run Microsoft Defender's full scan and, if anything was found, its offline scan as a second opinion. If the symptoms are gone after the plan and both scans are clean, there is nothing more to do.

Sources

More removal guides

Remove porterneuman.mx: PowerShell and JavaScript files tied to the AveMaria remote access trojan, and what to do

porterneuman.mx is a web address where URLhaus found five script files in a WordPress plugin folder on 30 September 2026: four PowerShell stubs and one JavaScript file. One stub is tagged AveMariaRAT, a remote access...TrojansHigh riskUgnius Kiguolis ·

Remove Memz virus

Memz virus is the custom-made trojan that overwrites Windows boot sequence with Nyan Cat meme animation Memz virus is the trojan originally created by Leurak as viewer-made malware forTrojansHigh riskLucia Danes ·

Remove qpwot.cfd: a server handing out scripts that lead to the MassLogger and VIP Keylogger stealers, and what to do if one ran

qpwot.cfd is a web address that URLhaus listed seven times on 6 October 2026 for JavaScript files and PowerShell files named secured_stub.ps1, tagged MassLogger and VIPKeylogger, two keyloggers that steal passwords...TrojansHigh riskUgnius Kiguolis ·

Remove www.beinke-aufzuege.de: a hacked website hosting FormBook PowerShell stubs, and what to do if a script fetched them

www.beinke-aufzuege.de is the address of a German website that URLhaus lists for four PowerShell files tagged Formbook, a password stealer for Windows, hidden in random folders inside the site's own Joomla media...TrojansHigh riskUgnius Kiguolis ·

Questions and experiences: CapraRAT

Still seeing it, or found something we did not cover? Ask here: members and our editors answer. Reading is open; writing needs a free account.

0 comments

…

5,441 members already hereReading, writing, commenting and voting. 0 verified · 166 joined this year