HaxRat — Take Total Control on Android Remotely

HaxRat — Take Total Control on Android Remotely

HaxRat is a cloud based remote android management suite in simple word it is a Android RAT, powered by NodeJS. It works in Linux and Termux (Android).

haxrat github tool made by hax4us control android remotely

Previously we have featured an article on L3MON, HaxRat is based on L3MON but much more powerful then L3MON. It have some extra features like screenshot, screen recording, front and rear camera recording. This is developed by Hax4us (Lokesh Pandey). The Key features of HaxRat are following:

Key Features of HaxRat

  • Screenshot Capture.
  • Screen Recorder.
  • Rear Camera Recorder.
  • Front Camera Recorder.
  • Lock Device.
  • GPS Logging.
  • Microphone Recording.
  • View Contacts.
  • SMS Logs.
  • Send SMS.
  • Call Logs.
  • View Installed Apps.
  • View Stub Permissions.
  • Live Clipboard Logging.
  • Live Notification Logging.
  • View WiFi Networks (logs previously seen).
  • File Explorer & Downloader.
  • Command Queuing.
  • Built In APK Builder.

We can easily install this suite on Linux , we also can install it on our Android phone by using Termux.


Installing HaxRat on Kali Linux

The installation process is the same as we did in our L3MON tutorial. We have detailed discussion on our that post So we are not going to explain the commands.

First we install JRE in Kali by using following command:

sudo apt-get install openjdk-8-jre

Then we download NodeJs in our system by applying following command:

curl -sL https://deb.nodesource.com/setup_13.x | sudo bash -

Now we install NodeJs by preceding following command:

sudo apt-get install -y nodejs

Now we need pm2 process manager to install this we use following command:

sudo npm install pm2 -g

Now we clone haxRat from it’s GitHub repository by using following command:

git clone https://github.com/Hax4us/haxRat

Then we navigate to server directory under haxRat by using cd command:

cd /haxRat/server

Then we need to install dependencies by using following command:

npm install

Then we start the server by using following command:

node index.js

Now we can see our server in our browser http://localhost:22533 there will be a login page as following screenshot:

haxrat login panel

Now we stop this server by using CTRL+C command. Now what to do ? Login ? But where are the credentials?  We have talked before how to create a custom credential on our older L3MON tutorial. Otherwise check the haxRat GitHub repository for default credentials.


After login we can see the main page as shown in the following screenshot:

haxrat dashboard termux



Now we go to the APK Builder page and give our local IP address and click on build.


If got  error like “Wrong java Version installed…..” this when building APK then try following command:

sudo update-alternatives --config java

Then Then we type 2 and enter.

Then we stop our running haxRat server by CTRL+C and start it again this problem will be solved.


Now we can build Spy APK and send it to victim, whenever victim install it and grant the permission. Or if we got victim’s phone in hand then we can implement this.


We got the victim in our haxRat dashboard like following screenshot:


haxrat dashboard

Now in the manage section we can manage the Android device totally. Magics will start from here.

Installed Android Apps
File Manager
Recording from front Camera

Installing HaxRat on Android (using Termux)


This is easy to installed in Termux. We try following commands one after another to install and configure haxRat.

apt install nodejs
git clone https://github.com/hax4us/haxRat.git
cd haxRat/server
npm install
mkdir ~/haxrat
haxrat
node index.js

In our browser we navigate to http://<Local IP>:22533 and we will be the login screen of haxRat.


This video by the developer is described how to install haxRat in Termux / Android:

This is how we can start the haxrat server and take control of any android device on our local network. We also can run this on wide network or internet by using PortMap service.

Disclaimer

Provides
no warranty with this software and will not be responsible for any
direct or indirect damage caused due to the usage of this tool or this
tutorial.
HaxRat is built and our article is documented for both Educational and Internal use ONLY
.

Getting any problem during installing or configuring HaxRat ? Feel free
to contact us by commenting with error details on below comment section or on the YouTube video this video is uploaded by the developer himself.
For more tutorials like this subscribe our newsletter to get updated.
Also we post updates on our Twitter and Medium make sure to follow us there.

KP AKA Koushik Pal is a Security researcher and specialist focused on educating about Linux for cybersecurity and URL‑masking vulnerabilities. Creator of MaskPhish, a well‑known open‑source bash-based URL‑masking tool. Linux enthusiasts Active speaker, trainer, and advocate for secure web practices.

68 comments

comments user
anonymus

FOR DEFAULT PASSWORD WE HAVE TO DOWNLOAD FILE?

comments user
Kali Linux

You may, otherwise you can try another method and generate your custom username and password . Go to our L3MON tutorial. This tool is based on L3MON so that will work finely.

comments user
blogger

nice tool admin,can you please post how to make pdf or a picture backdoor for android

comments user
Kali Linux

Hey, Thanks for the suggestion. We will keep in mind.

comments user
Unknown

please need help
when installling "sudo npm install pm2 -g"
i receive this messagge:"sudo: npm : commande introuvable"

comments user
Kali Linux

The npm file should be in /usr/local/bin/npm. If it's not there, install node.js again.

comments user
Unknown

I TRIED TO REINSTALL NODE.JS.BUT THE PROBLEM IS THE SAME AND I GOT THE SAME MESSAGE(npm command not found)
my system is windows 7 32bit thanks

comments user
Kali Linux

We suggest you to to to the official page of nmp and follow the instructions.

comments user
Unknown

unable to open java -jar /root/haxRat/server/app/factory/apktoll.jar…when i was trying to building payload

comments user
Kali Linux

To solve this we need full information that how you have installed it. We suggest a re-install for more details try the video. We think that apktool.jar file is missing from it's path or you might forgot to use sudo.

comments user
Yudip upreti

Please help me to fix bash: cd: /haxRat/server: No such file or directory

comments user
Kali Linux

Did you cloned haxRat from github. We think you need to do it again and follow our instructions carefully and you need to be in the right directory. Is says that you don't have these directory in our system, so please check it by ls command.

comments user
Anonymous

can I use ngrok for port forwarding?

comments user
Kali Linux

Yes, we can but the author of this tool suggest to use portmap services.

comments user
Anonymous

bro,
please make give detail information about QRLJACKING.
bro your content is awesome…

comments user
Kali Linux

Okey we will do a qrljacking tutorial but after some time, because we are working with some awesome contents. Thanks for your suggestion.

comments user
Unknown

the target phone will not connect. neither will mine. ive downloaded the apk and everything is there but i cant seem to get anything further than the download..please advise

comments user
Kali Linux

Tell us something about your connections. Which IP you have provided in APK building?

comments user
Anonymous

https://pastebin.com/PG8nuYXv

Defualt password is haxratserver

comments user
Anonymous

Do you have complete tutorial setting portmap to use haxRAT over internet?
Is the localhost:xxxx port is the port I should fill on the app builder?
I've tried many times, but has no luck
Thankyou

comments user
Anonymous

Is it possible the app we built using haxRAT accesible by others hackers?

comments user
Kali Linux

We did not tried it. But the developer of this tool told that he connects it with portmap and it works well.

comments user
Kali Linux

We did not got the point.

comments user
Anonymous

this is the error i get when i configure java
There is only one alternative in link group java (providing /usr/bin/java): /usr/lib/jvm/java-11-openjdk-amd64/bin/java
Nothing to configure.

comments user
Kali Linux

It's looks like you doesn't have installed Java in your system. Try following command to install it and follow the tutorial then:

sudo apt-get install openjdk-8-jdk

comments user
Unknown

Can we use 22222 in haxrat aswell??

comments user
Kali Linux

You can use any port number for it.

comments user
irfan

Hi I was tried the browser it's say bad login the all is ok admin and password I write and see bad login i use chrome and android mia3

comments user
Kali Linux

Did you followed all the steps on this article?

comments user
Hgg

Username kya h bhai

comments user
Anonymous

I installed the app in victims phone but after some time connection got lost and never got back

comments user
Kali Linux

This happens with everyone. You need to make a persistence backdoor inside the phone. There are lots of tutorial on internet how to create persistence backdoor on android. You can try them. Thanks.

comments user
Unknown

this specific command is not working in kali linux virtual box

sudo npm install pm2 -g

it says sudo: npm: comand not found please help me asap because i haven't progressed after getting stuck at this command

comments user
Kali Linux

This problem comes because you don't have npm. You need to install it by using following command:

sudo apt-get install npm

Thanks.

comments user
Anonymous

I have installed both L3MON and HaxRat – however the one issue I am getting is the IP address that I need to provide – I have a dynamic IP and not a static one – what is the workaround for the same ?

comments user
Kali Linux

We can suggest you no-ip services. This will make your dynamic IP static. Else you can ask your Internet service provider for a static IP (they might charge extra for it). No-Ip is a free service you can try it.

comments user
Aayush SC

which kali linux ios build are you using , my laptop is 64bit , i want to know which is the best bild where i can use these penetration tests ,there are many builds where L3MON and HAXRAT dose'nt work.

comments user
Unknown

What is user name and oassword in control pannel plz

comments user
Unknown

Sorry password

comments user
Kali Linux

We have talked before how to create a custom credential on our older L3MON tutorial. If you check the haxRat GitHub repository for default credentials then you might see some ads. We suggest you to just check the L3MON article's credential section only.

comments user
Unknown

Sir aap me aona video private q kiya hai ?

comments user
Unknown

Please answer me

comments user
Unknown

I fixed everything but can't see Devices even after that.

comments user
Kali Linux

That video was uploaded by the developer we can't say much about it.

comments user
Kali Linux

Can you send screenshot here (screenshot link) or on our telegram group.

comments user
Unknown

In WAN network Port forwarding Mandatory? if Mandatory then plz tell me when i used internet without Router then how port forward? help me plz and also tell me for Haxrat which port have to forwarding?

comments user
Kali Linux

Yes! In the case of WAN port forwarding is mandatory. Otherwise other devices can't reach to our network from the internet. We already have an article on this. Check SSH port forwarding without router article.

comments user
Unknown

sir i used ngrok for port forwarding. but still now not showing victim devices(my another devices that which other internet connection). haxrat page will open, apk creates easily then where can the problem be?

comments user
Anonymous

Sir i am getting " apkmod not found " problem after entering my ip in apk builder.

Any solution to that . I have installed apkmod from github but that not worked same problem 🙁

comments user
Kali Linux

Haxrat giving lots of errors.

The developer of Haxrat is in our Telegram group. In some recent talks he hints to discontinue the haxrat project because of lots of errors.

comments user
Anonymous

In my case, Everything was fine but after installing the apk server shows device is offline.

comments user
Kali Linux

The developer of Haxrat (Lokesh) is in our Telegram Family. You can chat with him. In some recent talks he hints to discontinue the haxrat project because of lots of errors, and he is not getting enough time to fix them.

comments user
Erwin Rommel

Guys do we have a channel of forum where we discuss tools only – I mean RATs Malwares etc ? The current Telegram channel is more dedicated to installing Termux and/or Kali only (a majortiy of it)

comments user
Kali Linux

RAT's and Malwares is seems to be not so ethical. Many of group members will take advantage of it for illegal things. We more focus on ethical things and security. In our current group there are lot of newbies. They are just learning things. They will learn the things we just need to help them. We will be a strong community/family. If we allow such type of things we will become a black hat team. That's what we don't want. We want to be a community of security experts not hackers. Hope you will understand.

comments user
Shinbe

i tried to use some function such as lock, screenshot, screenrecord … but it doesnt work

comments user
Kali Linux

Hello Shinnbe, We are sorry for that is not working. I had talked personally to the developer of haxrat. He says me that he didn't getting time to update this tool, may be he discontinued this project and archive this.

comments user
Anonymous

Hello Developer,
Please help me to know which port to forward in our router (.i.e.:- 22533 or 22222 and after that using which ip and port should we build the apk(.i.e public ip and 22533 or 22222) to build apk? so that it will be accessible over the internet

comments user
Anonymous

it does not work with real android devices does any one have any solutions

comments user
Anonymous

yes i really does not works in real android device with android8.1

comments user
Anonymous

does this tool works anymore? tried, but no device number or anything. used portmap service to hide but nothing works.

comments user
Anonymous

You are right. These kind of tools are not available on public now. They made it paid tools now.

comments user
Anonymous

If we build an apk file, can we use it to attack on several devices?

comments user
Anonymous

what is ip in building apk file?

comments user
RatBastiche

when I get to the step "node index.js" (actually I have to run it as sudo node index.js) I get the following output and then I am stuck ….

/////// Begin copy / paste \\\

Server Started!
http://localhost:22533
/haxRat/server/index.js:30
let client_io = IO.listen(CONST.control_port);
^

TypeError: IO.listen is not a function
at Object. (/haxRat/server/index.js:30:20)
at Module._compile (node:internal/modules/cjs/loader:1358:14)
at Module._extensions..js (node:internal/modules/cjs/loader:1416:10)
at Module.load (node:internal/modules/cjs/loader:1208:32)
at Module._load (node:internal/modules/cjs/loader:1024:12)
at Function.executeUserEntryPoint [as runMain] (node:internal/modules/run_main:174:12)
at node:internal/main/run_main_module:28:49

Node.js v20.16.0
craig@BB4Eva:/haxRat/server$

///// End copy / paste \\\

Oh the horror! Any chance this makes good sense to anyone who wouldn't mind taking a moment to offer some constructive advice? This has me stuck like Chuck and I'm not sure what I need to do to get this exercise back on track again.

Thank you in advance!

comments user
RatBastiche

PS . … No main page ever materializes either, in case that was in question… I have to assume the reason is because the command "sudo node index.js" failed catastrophically and did not complete … therefore, a number of key modifications to necessary files and / or folders did not occur … but that's just a guess, and I looked …. but as it turns out, I am fresh out of clues!

So again, thanks in advance.

comments user
Anonymous

below creds working for me, in current date
username : admin
password: haxratserver

comments user
Sajid kakepoto

I have build the apk but it is not downloading please help me

    comments user
    KP

    This tool is not maintained by the developer. However you can ask him on his GitHub page. Thanks.

Post Comment