RAT
Advanced Espionage Tool Adware AI Android APP APPX file ATM Malware Backdoor Banking Bookit Bot BotNet Code-injection CoinMiners Crypt Cryptocurrency Cryptojacking CyberSpy Data Wiper DDoS DEAMON Destructive Malware DNS Backdoor Downloader Driver Droper EDR and AV Killer ELF ENGINE Espionage Exploit Families Fileless FRAMEWORK FUD Engine Go GPT GPU GRU Malware HTML ICS InfoStealer Injector iOS IoT IRC ISS Java JavaScipt JSON Keylogger Killer Kit LINUX Loader Maas MacOS Macro Malware Military Malware Miner Mobil MultiOS nmp OS OSX OT malware P2P virus Password STEALER Pay-per-install (PPI) PoS Malware PowerShell Program PyPI Python QR trojan Ransom Raspberry RAT Roque Rootkit SMS Spy Spyware SQL Malware Stealer SymbOS Tool Trojan TV UEFI bootkit USB Utility VBA Macro VBE VBS VHD malware Virus Vishing toolset VMware ESXi Windows Wipper WM virus Worm Wrapper
| 02.09.26 | Mirax | Mirax: a new Android RAT turning infected devices into potential residential proxy nodes | MALWARE | RAT |
| 02.09.26 | StreamRat | Uncovering StreamRat: From Meta Ads to Full Device Takeover | MALWARE | RAT |
| 28.08.26 | Spark RAT | Cambodia-focused cluster uses multistage infection chain with localized lures | MALWARE | RAT |
| 19.08.26 | NodeEdgeRAT | (JavaScript), which ships its entire functionality spanning command execution, file management, and file transfer in one script. | MALWARE | RAT |
| 19.08.26 | GoginRAT | (Go), which has architectural similarities with NomadRAT and uses a separate transmitter for C2, and implements file system and shell capabilities as independent plugins. The results of the plugin execution are routed through a shared callback. | MALWARE | RAT |
| 19.08.26 | NomadRAT | (C++), which features a main orchestrator, a dedicated transmitter library that handles all C2 traffic, and plugins fetched from the server by numeric identifiers only when they are required. | MALWARE | RAT |
| 19.08.26 | CookiETagRAT | (C++), which uses HTTP Cookie / ETag response headers as C2 to receive and execute commands. | MALWARE | RAT |
| 19.08.26 | DriveSilkRAT | (.NET/C++), which uses Google Drive as command-and-control (C2) to poll a specific folder for tasking, run it through an in-memory .NET plugin system, and upload the results of the execution back to the same folder. It supports 12 plugins for process listing, system and network enumeration, file management, and command execution. | MALWARE | RAT |
| 14.08.26 | WindRelay | Gone with the WindRelay: A New Malware Combo Behind a Growing Fraud Scheme | MALWARE | RAT/NFC |
| 14.08.26 | WindRelay | Gone with the WindRelay: A New Malware Combo Behind a Growing Fraud Scheme | MALWARE | RAT/NFC |
| 30.07.26 | AtlasRAT | Not Every Fox is Silver: Inside an AtlasRAT loader chain | MALWARE | RAT |
| 30.07.26 | AtlasRAT | Not Every Fox is Silver: Inside an AtlasRAT loader chain | MALWARE | RAT |
| 29.07.26 | DEV#POPPER | Two Joyfill npm Beta Releases Compromised to Deliver DEV#POPPER Remote Access Trojan | MALWARE | RAT |
| 28.07.26 | MedusaHVNC | A Hidden Desktop That Steals Live Windows Sessions | MALWARE | RAT |
| 23.07.26 | msaRAT | Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel | MALWARE | RAT |
| 18.07.26 | Starland RAT | Cisco Talos is disclosing UAT-11795, a sophisticated, Russian-speaking, financially motivated adversary that has been conducting a malicious campaign targeting users in the U.S. and Europe since at least June 2025. | MALWARE | RAT |
| 16.07.26 | Miasma RAT | AsyncAPI Packages Compromised with Miasma RAT | MALWARE | RAT |
| 14.07.26 | LabubaRAT | LabubaRAT: A Rust Based Remote Access Tool Masquerading as NVIDIA Software | MALWARE | RAT |
| 08.07.26 | Oblivion | Oblivion: The New $300 Android RAT That Beats Every Major Phone Manufacturer’s Security | MALWARE | RAT |
| 06.07.26 | QuimaRAT | Novel Java-Based QuimaRAT Targets Windows, macOS, and Linux | MALWARE | RAT |
| 05.07.26 | ChocoPoC | This article details a campaign targeting vulnerability researchers with "ChocoPoC" malware embedded inside trojanised Python dependencies. Exploiting the pressure to quickly test new vulnerabilities, threat actors distribute a persistent Remote Access Trojan (RAT) that exfiltrates data and harvests credentials from compromised developer environments. | MALWARE | RAT |
| 04.07.26 | Glitch SPY | CRIL analyzes Glitch SPY, an Android RAT with 70+ commands, crypto-clipping, and a silent remote browser, giving attackers full device control. | MALWARE | RAT |
| 04.07.26 | Banana RAT | In this blog entry, researchers from the TrendAI™ MDR team discuss how they mapped the full end-to-end operation of SHADOW-WATER-063’s Banana RAT banking malware by analyzing server-side artifacts and victim-side data. | MALWARE | RAT |
| 02.07.26 | AsyncRAT Reloaded | AsyncRAT Reloaded: Using Python and TryCloudflare for Malware Delivery Again | MALWARE | RAT |
| 16.06.26 | NarwhalRAT | Analysis of APT37 NarwhalRAT Leveraging MS-Themed Phishing and Dead-drop C2 | MALWARE | RAT |
| 07.06.26 | Atlas RAT | TA4922: The Suspected Chinese Crime Group is Going Global | MALWARE | RAT |
| 05.06.26 | Argamal | In April 2026, we discovered a new malware campaign targeting players of “hentai” games. Once launched, the infected games install a previously unknown malicious implant on the user’s machine. | MALWARE | RAT |
| 04.06.26 | DesckVB RAT | DesckVB RAT first emerged around February 2026 and has been making the rounds ever since. The activity originated from a malspam kit. | MALWARE | RAT |
| 01.06.26 | TencShell | Cato CTRL Threat Research: Suspected China-Linked Threat Actor Targets Global Manufacturer with Undocumented TencShell Malware | MALWARE | RAT |
| 27.05.26 | BTMOB | BTMOB: A stealthy RAT burrowing deep into Android devices | MALWARE | RAT |
| 25.05.26 | RemotePE | RemotePE: The Lazarus RAT that lives in memory | MALWARE | RAT |
| 08.05.26 | Quasar Linux | Quasar Linux (QLNX) – A Silent Foothold in the Supply Chain: Inside a Full-Featured Linux RAT With Rootkit, PAM Backdoor, Credential Harvesting Capabilities | MALWARE | RAT |
| 06.05.26 | CloudZ RAT | CloudZ RAT potentially steals OTP messages using Pheno plugin | MALWARE | RAT |
| 17.04.26 | PhantomPulse | Phantom in the vault: Obsidian abused to deliver PhantomPulse RAT | MALWARE | RAT |
| 14.04.26 | JanelaRAT | JanelaRAT: a financial threat targeting users in Latin AmericaLABYRINT | MALWARE | RAT |
| 08.04.26 | ROKRAT | Scarcruft’s ROKRAT Malware: Recent Changes | MALWARE | RAT |
|
03.04.26 |
A laughing RAT: CrystalX combines spyware, stealer, and prankware features |
RAT |
||
|
31.03.26 |
Trust the Tunnel, Get the Trojan: Silver Fox Delivers AtlasCross RAT via Weaponized VPN Installers |
RAT |
||
|
12.03.26 |
TAXISPY RAT : Analysis of TaxiSpy RAT – Russian Banking – Focused Android Malware with Full Remote Control |
RAT |
||
|
04.03.26 |
Malicious Packagist Packages Disguised as Laravel Utilities Deploy Encrypted RAT |
RAT |
||
|
03.03.26 |
SloppyLemming Deploys BurrowShell and Rust-Based RAT to Target Pakistan and Bangladesh |
RAT |
||
|
27.02.26 |
While hunting for C2 infrastructure on Censys, we uncovered a suspected
state-affiliated cluster targeting Kazakh and Afghan entities in a
persistent campaign, |
RAT |
||
|
27.02.26 |
This repository accompanies a full technical report documenting an
active malware ecosystem centered around DesckVB RAT, a modular .NET
Remote |
RAT |
||
|
27.02.26 |
Steaelite RAT Enables Double Extortion Attacks from a Single Panel |
RAT |
||
|
21.02.26 |
Uncovering a Recent Pulsar RAT Sample in the Wild |
RAT |
||
|
11.02.26 |
No Fool's Errand: The Koalemos RAT Campaign |
RAT |
||
|
19.01.26 |
Dissecting CrashFix: KongTuke's New Toy |
RAT |
||
|
10.01.26 |
Reborn in Rust: Muddy Water Evolves Tooling with RustyWater Implant |
RAT |
||
|
08.01.26 |
Malicious NPM Packages Deliver NodeCordRAT |
RAT |
||
|
13.12.25 |
Cracking ValleyRAT: From Builder Secrets to Kernel Rootkits |
RAT |
||
|
13.12.25 |
SetcodeRat Exposed: A Telegram Secret Stealing Trojan Customized for Chinese-speaking Regions |
RAT |
||
|
13.12.25 |
PyStoreRAT: A New AI-Driven Supply Chain Malware Campaign Targeting IT & OSINT Professionals |
RAT |
||
|
10.12.25 |
EtherRAT: DPRK uses novel Ethereum implant in React2Shell attacks |
RAT |
||
|
08.12.25 |
Return of ClayRat: Expanded Features and Techniques |
RAT |
||
|
05.12.25 |
Silver Fox’s Russian Ruse: ValleyRAT Hits China via Fake Microsoft Teams Attack |
RAT |
||
|
11.11.25 |
New Kimsuky Malware “EndClient RAT”: First Technical Report and IOCs |
RAT |
||
|
04.11.25 |
SleepyDuck malware invades Cursor through Open VSX |
RAT |
||
|
01.11.25 |
RL's analysis of an STD Group-operated RAT yielded file indicators to better detect the malware and two YARA rules. |
RAT |
||
|
30.10.25 |
Unpacking NetSupport RAT Loaders Delivered via ClickFix |
RAT |
||
|
30.10.25 |
Atroposia is a stealthy RAT with HRDP, credential theft, DNS hijacking & fileless exfiltration — aka cybercrime made easy for low-skill attackers. |
RAT |
||
|
30.10.25 |
LATAM baited into the delivery of PureHVNC |
RAT |
||
|
26.10.25 |
PhantomCaptcha | Multi-Stage WebSocket RAT Targets Ukraine in Single-Day Spearphishing Operation |
RAT |
||
|
25.10.25 |
TransparentTribe targets Indian military organisations with DeskRAT |
RAT |
||
|
25.10.25 |
PhantomCaptcha | Multi-Stage WebSocket RAT Targets Ukraine in Single-Day Spearphishing Operation |
RAT |
||
|
21.10.25 |
Salty Much: Darktrace’s view on a recent Salt Typhoon intrusion |
RAT |
||
|
20.10.25 |
From China to Malaysia, FortiGuard Labs traces a hacker group’s shifting campaigns and evolving malware delivery tactics across Asia |
RAT |
||
|
11.10.25 |
New Stealit Campaign Abuses Node.js Single Executable Application |
RAT |
||
|
11.10.25 |
New Stealit Campaign Abuses Node.js Single Executable Application |
RAT |
||
|
10.10.25 |
ClayRat: A New Android Spyware Targeting Russia |
RAT |
||
|
03.10.25 |
Datzbro: RAT Hiding Behind Senior Travel Scams |
RAT |
||
|
13.09.25 |
FortiGuard Labs uncovers MostereRAT’s use of phishing, EPL code, and remote access tools like AnyDesk and TightVNC to evade defenses and seize full system control. |
RAT |
||
|
11.09.25 |
AsyncRAT in Action: Fileless Malware Techniques and Analysis of a Remote Access Trojan |
RAT |
||
|
10.09.25 |
ZynorRAT technical analysis: Reverse engineering a novel, Turkish Go-based RAT |
RAT |
||
|
09.09.25 |
MostereRAT Deployed AnyDesk/TightVNC for Covert Full Access |
RAT |
||
|
05.09.25 |
From CastleLoader to CastleRAT: TAG-150 Advances Operations with Multi-Tiered Infrastructure |
RAT |
||
|
02.09.25 |
Operation HanKook Phantom: North Korean APT37 targeting South Korea |
RAT |
||
|
24.08.25 |
XenoRAT malware campaign hits multiple embassies in South Korea |
RAT |
||
|
21.08.25 |
A new malware loader delivering infostealers and RATs |
RAT |
||
|
19.08.25 |
GodRAT – New RAT targeting financial institutions |
RAT |
||
|
05.08.25 |
PlayPraetor's evolving threat: How Chinese-speaking actors globally scale an Android RAT |
RAT |
||
|
19.07.25 |
DslogdRAT Malware Installed in Ivanti Connect Secure |
RAT |
||
|
16.07.25 |
Researchers from The DFIR Report, in partnership with Proofpoint, have identified a new and resilient variant of the Interlock ransomware group’s remote access trojan (RAT). |
RAT |
||
|
08.07.25 |
DRAT V2: Updated DRAT Emerges in TAG-140’s Arsenal |
RAT |
||
|
24.06.25 |
Malware targeting Fortinet devices |
RAT |
||
|
24.06.25 |
A post-exploitation tool for remote shell access & TCP tunnelling through a victim device. |
RAT |
||
|
21.06.25 |
Famous Chollima deploying Python version of GolangGhost RAT |
RAT |
||
|
08.06.25 |
A simple customer query leads to a rabbit hole of backdoored malware and game cheats |
RAT |
||
|
06.06.25 |
DuplexSpy RAT: Stealthy Windows Malware Enabling Full Remote Control and Surveillance |
RAT |
||
|
04.06.25 |
From open-source to open threat: Tracking Chaos RAT’s evolution |
RAT |
||
|
30.05.25 |
Malware with wide range of capabilities ranging from RAT to ransomware. |
RAT |
||
|
30.05.25 |
Malware with wide range of capabilities ranging from RAT to ransomware. |
RAT |
||
|
29.05.25 |
The MS-DOS Header is a 64-byte structure at the beginning of a PE file. Along with the DOS stub, the DOS header is responsible for MS-DOS backward compatibility. |
RAT |
||
|
28.05.25 |
Inside a VenomRAT Malware Campaign |
RAT |
||
|
24.05.25 |
Following the spiders: Investigating Lactrodectus malware |
RAT |
||
|
21.05.25 |
Pure Harm: PureRAT Attacks Russian Organizations |
RAT |
||
|
16.05.25 |
Fileless Execution: PowerShell Based Shellcode Loader Executes Remcos RAT |
RAT |
||
|
25.04.25 |
DslogdRAT Malware Installed in Ivanti Connect Secure |
RAT |
||
|
18.04.25 |
IronHusky updates the forgotten MysterySnail RAT to target Russia and Mongolia |
RAT |
||
|
15.04.25 |
New Malware Variant Identified: ResolverRAT Enters the Maze |
RAT |
||
|
15.04.25 |
Goodbye HTA, Hello MSI: New TTPs and Clusters of an APT driven by Multi-Platform Attacks |
RAT |
||
|
28.03.25 |
ANALYSIS OF A DISCORD-BASED REMOTE ACCESS TROJAN (RAT) |
RAT |
||
|
28.03.25 |
Analysis of Konni RAT: Stealth, Persistence, and Anti-Analysis Techniques |
RAT |
||
|
18.03.25 |
StilachiRAT analysis: From system reconnaissance to cryptocurrency theft |
RAT |
||
|
07.03.25 |
Unveiling EncryptHub: Analysis of a multi-stage malware campaign |
RAT |
||
|
06.03.25 |
The evolution of Dark Caracal tools: analysis of a campaign featuring Poco RAT |
RAT |
||
|
27.02.25 |
ValleyRAT Insights: Tactics, Techniques, and Detection Methods |
RAT |
||
|
25.02.25 |
Silent Killers: Unmasking a Large-Scale Legacy Driver Exploitation Campaign |
RAT |
||
|
10.02.25 |
Rat Race: ValleyRAT Malware Targets Organizations with New Delivery Techniques |
RAT |
||
|
05.02.25 |
AsyncRAT Reloaded: Using Python and TryCloudflare for Malware Delivery Again |
RAT |
||
|
10.01.25 |
The NonEuclid Remote Access Trojan (RAT) is a type of malicious software
that enables unauthorised remote access and control of a victim’s |
RAT |
||
|
02.01.25 |
Quasar RAT Disguised as an npm Package for Detecting Vulnerabilities in Ethereum Smart Contracts |
RAT |
||
|
22.12.24 |
The latest version of WezRat was recently distributed to multiple
Israeli organizations in a wave of emails impersonating the Israeli
National |
RAT |
||
|
18.12.24 |
Vishing via Microsoft Teams Facilitates DarkGate Malware Intrusion |
RAT |
||
|
17.12.24 |
Until 2016, the foreign security manufacturer Forcepoint disclosed the existence of the Manlinghua organization for the first time [1] ,.. |
RAT |
||
|
17.12.24 |
Bitter Group Launches New Trojan Miyarat, Domestic Users Become Primary Ttargets |
RAT |
||
|
03.12.24 |
Horns&Hooves campaign delivers NetSupport RAT and BurnsRAT |
RAT |
||
|
03.12.24 |
Horns&Hooves campaign delivers NetSupport RAT and BurnsRAT |
RAT |
||
|
26.11.24 |
Chinese Hackers Use GHOSTSPIDER Malware to Hack Telecoms Across 12+ Countries |
RAT |
||
|
18.11.24 |
LodaRAT: Established Malware, New Victim Patterns |
RAT |
||
|
18.11.24 |
Mr.Skeleton RAT - new malware based on the njRAT code |
RAT |
||
|
15.11.24 |
Malware Spotlight: A Deep-Dive Analysis of WezRat |
RAT |
||
|
08.11.24 |
Cloudy With a Chance of RATs: Unveiling APT36 and the Evolution of ElizaRAT |
RAT |
||
|
27.10.24 |
DarkVision RAT is a highly customizable remote access trojan (RAT) that first surfaced in 2020,... |
RAT |
||
|
27.09.24 |
DCRat Targets Users with HTML Smuggling |
RAT |
||
|
25.09.24 |
Security Brief: Actor Uses Compromised Accounts, Customized Social Engineering to Target Transport and Logistics Firms with Malware |
RAT |
||
|
23.09.24 |
Gleaming Pisces Poisoned Python Packages Campaign Delivers PondRAT Linux and MacOS Backdoors |
RAT |
||
|
19.09.24 |
Exotic SambaSpy is now dancing with Italian users |
RAT |
||
|
21.08.24 |
MoonPeak malware from North Korean actors unveils new details on attacker infrastructure |
RAT |
||
|
16.08.24 |
SharpRhino – New Hunters International RAT Identified by Quorum Cyber |
RAT |
||
|
16.08.24 |
A Deep Dive into a New ValleyRAT Campaign Targeting Chinese Speakers |
RAT |
||
|
05.08.24 |
Bloody Wolf strikes organizations in Kazakhstan with STRRAT commercial malware |
RAT |
||
|
02.08.24 |
BingoMod: The new android RAT that steals money and wipes data |
RAT |
||
|
02.08.24 |
A trojan for Linux with a wide range of functions and the ability to be remotely controlled via a Telegram bot. The source code is written in Go and encrypted with RSA. |
RAT |
||
|
02.08.24 |
At the first stage, the dropper checks the parameters (arguments) used for its launch: this impacts the intermediate persistence stage. |
RAT |
||
|
13.07.24 |
DarkGate: Dancing the Samba With Alluring Excel Files |
RAT |
||
|
11.07.24 |
New Malware Campaign Targeting Spanish Language Victims |
RAT |
||
|
17.06.24 |
Ministry of Defence of the Netherlands uncovers COATHANGER,a stealthy Chinese FortiGate RAT |
RAT |
||
|
17.06.24 |
Botnet Installing NiceRAT Malware |
RAT |
||
|
14.06.24 |
In Bad Company: JScript RAT and CobaltStrike |
RAT |
||
|
13.06.24 |
Noodle RAT: Reviewing the Backdoor Used by Chinese-Speaking Groups |
RAT |
||
|
12.06.24 |
Technical Analysis of the Latest Variant of ValleyRAT |
RAT |
||
|
05.06.24 |
During 23, DarkGate made a comeback with a version full of new features, becoming one of the most preferred Remote Access Trojans (RATs) by malicious actors. |
RAT |
||
|
03.06.24 |
Fake Browser Updates delivering BitRAT and Lumma Stealer |
RAT |
||
|
29.05.24 |
ALLASENHA: ALLAKORE VARIANT LEVERAGES AZURE CLOUD C2 TO STEAL BANKING DETAILS IN LATIN AMERICA |
RAT |
||
|
25.05.24 |
BLOODALCHEMY used in attacks targeting government organizations in Southern and Southeastern Asia is in fact an updated version of Deed RAT, |
RAT |
||
|
25.05.24 |
Malware Transmutation! - Unveiling the Hidden Traces of BloodAlchemy |
RAT |
||
|
18.05.24 |
Artificial Sweetener: SugarGh0st RAT Used to Target American Artificial Intelligence Experts |
RAT |
||
|
27.04.24 |
From BYOVD to a 0-day: Unveiling Advanced Exploits in Cyber Recruiting Scams |
RAT |
||
|
25.04.24 |
Analysis of Pupy RAT Used in Attacks Against Linux Systems |
RAT |
||
|
11.04.24 |
eXotic Visit campaign: Tracing the footprints of Virtual Invaders |
RAT |
||
|
08.04.24 |
Bing ad for NordVPN leads to SecTopRAT |
RAT |
||
|
05.04.24 |
AGENT TESLA TARGETING UNITED STATES & AUSTRALIA: REVEALING THE ATTACKERS’ IDENTITIES |
RAT |
||
|
02.04.24 |
VenomRAT: A remote access tool with dangerous consequences |
RAT |
||
|
30.03.24 |
DinodasRAT Linux implant targeting entities worldwide |
RAT |
||
|
27.03.24 |
Trochilus is a C++ written RAT, which is available on GitHub. |
RAT |
||
|
22.03.24 |
Revenge RAT via malicious PPAM in Latin America, Portugal and Spain |
RAT |
||
|
22.03.24 |
Insight into ESET telemetry statistics about AceCryptor in H2 23 with a focus on Rescoms campaigns in European countries |
RAT |
||
|
20.03.24 |
Enigma Software notes that NetSupport Manager is a genuine application, which was first released about twenty years ago. |
RAT |
||
|
20.03.24 |
APT37's ROKRAT HWP Object Linking and Embedding |
RAT |
||
|
14.03.24 |
zgRAT is a Remote Access Trojan malware which sometimes drops other malware such as AgentTesla malware. |
RAT |
||
|
14.03.24 |
According to Subex Secure, CyberGate is a Remote Access Trojan (RAT) that allows an attacker to gain unauthorized access to the victim’s system. |
RAT |
||
|
13.03.24 |
STRRAT is a Java-based RAT, which makes extensive use of plugins to provide full remote access to an attacker, as well as credential stealing, key logging and additional plugins. |
RAT |
||
|
07.03.24 |
AhnLab Security intelligence Center (ASEC) has recently discovered the distribution of backdoor malware via aNotepad, a free online notepad platform. |
RAT |
||
|
07.03.24 |
The malware has been released on github at https://github.com/EVLF/Cypher-Rat-Source-Code |
RAT |
||
|
02.03.24 |
The Art of Domain Deception: Bifrost's New Tactic to Deceive Users |
RAT |
||
|
28.02.24 |
Analysis of Nood RAT Used in Attacks Against Linux (Gh0st RAT’s Variant) |
RAT |
||
|
27.02.24 |
We have discovered some of the most dangerous threats and nation state attacks in our space – including the Kaseya MSP breach and the more_eggs malware. |
RAT |
||
|
27.02.24 |
We have discovered some of the most dangerous threats and nation state attacks in our space – including the Kaseya MSP breach and the more_eggs malware. |
RAT |
||
|
22.02.24 |
To Russia With Love: Assessing a KONNI-Backdoored Suspected Russian Consular Software Installer |
RAT |
||
|
12.02.24 |
The U.S. Justice Department (DoJ) on Friday announced the seizure of online infrastructure that was used to sell a remote access trojan (RAT) called Warzone RAT. |
RAT |
||
|
07.02.24 |
Successful exploitation of the flaw paved the way for the deployment of a backdoor dubbed COATHANGER from an actor-controlled server that's designed to.. |
RAT |
||
|
05.02.24 |
ESET researchers discovered several Android apps carrying VajraSpy, a RAT used by the Patchwork APT group |
RAT |
||
|
29.01.24 |
AllaKore is a simple Remote Access Tool written in Delphi, first observed in 2015 but still in early stages of development. |
RAT |
||
|
29.01.24 |
It is a backdoor commonly distributed as an encoded binary file downloaded and decrypted by shellcode following the exploitation of weaponized documents. |
RAT |
||
|
17.01.24 |
Remcos RAT Being Distributed via Webhards |
RAT |
||
|
09.01.24 |
A GAMER TURNED MALWARE DEVELOPER : DIVING INTO SILVERRAT AND IT’S SYRIAN ROOTS |
RAT |
||
|
09.01.24 |
A GAMER TURNED MALWARE DEVELOPER : DIVING INTO SILVERRAT AND IT’S SYRIAN ROOTS |
RAT |
||
|
05.01.24 |
Bandook - A Persistent Threat That Keeps Evolving |
RAT |
||
|
05.01.24 |
Ukraine Targeted by UAC-0050 Using Remcos RAT Pipe Method for Evasion |
RAT |
||
|
05.01.24 |
Bandook - A Persistent Threat That Keeps Evolving |
RAT |
||
|
05.01.24 |
Ukraine Targeted by UAC-0050 Using Remcos RAT Pipe Method for Evasion |
RAT |
||
|
29.12.23 |
SectopRAT, aka ArechClient2, is a .NET RAT with numerous capabilities including multiple stealth functions. |
RAT |
||
|
29.12.23 |
According to ProofPoint, FlawedGrace is written in C++ and can be categorized as a Remote Access Trojan (RAT). |
RAT |
||
|
24.12.23 |
A rewrite of Bazarloader in the Nim programming language. |
RAT |
||
|
14.12.23 |
DCRat is a typical RAT that has been around since at least June 2019. |
RAT |
||
|
07.12.23 |
Curse of the Krasue: New Linux Remote Access Trojan targets Thailand |
RAT |
||
|
01.12.23 |
New SugarGh0st RAT targets Uzbekistan government and South Korea |
RAT |
||
|
01.12.23 |
According to Security Ninja, Gh0st RAT (Remote Access Terminal) is a
trojan “Remote Access Tool” used on Windows platforms, |
RAT |
||
|
28.11.23 |
This is third stage backdoor mentioned in the Kaspersky blog, "Andariel evolves to target South Korea with ransomware". |
RAT |
||
|
25.11.23 |
Konni is a remote administration tool, observed in the wild since early 2014. |
RAT |
||
|
20.11.23 |
New Java-Based Sayler RAT Targets Polish Speaking Users |
RAT |
||
|
17.11.23 |
Information stealer which uses AutoIT for wrapping. |
RAT |
||
|
16.11.23 |
BlueShell malware used in APT attacks targeting Korea and Thailand |
RAT |
||
|
09.11.23 |
Double Action, Triple Infection, and a New RAT: SideCopy’s Persistent Targeting of Indian Defence |
RAT |
||
|
09.11.23 |
AllaKore is a simple Remote Access Tool written in Delphi, first observed in 2015 but still in early stages of development. |
RAT |
||
|
06.11.23 |
The Rising Threat of Covert Cyber Attacks through Google Calendar |
RAT |
||
|
27.10.23 |
Securonix Security Advisory: Python-Based PY#RATION Attack Campaign Leverages Fernet Encryption and Websockets to Avoid Detection |
RAT |
||
|
27.10.23 |
In this course, you will learn exfiltration over alternative protocol: exfiltration over unencrypted/obfuscated non-C2 protocol using Powershell RAT. |
RAT |
||
|
20.10.23 |
It is a backdoor commonly distributed as an encoded binary file downloaded and decrypted by shellcode following the exploitation of weaponized documents. |
RAT |
||
|
19.10.23 |
VenomRAT - new, hackforums grade, reincarnation of QuassarRAT |
RAT |
||
|
16.10.23 |
According to ThreatFabric, this is a malware family based on apk.ermac. The name hook is the self-advertised named by its vendor DukeEugene. |
RAT |
||
|
14.10.23 |
Unit 42 observed threat actor Tropical Scorpius using this RAT in operations where also Cuba ransomware was deployed. |
RAT |
||
|
13.10.23 |
Phylum Discovers SeroXen RAT in Typosquatted NuGet Package |
RAT |
||
|
08.10.23 |
HyperBro is a RAT that has been observed to target primarily within the gambling industries, though it has been spotted in other places as well. |
RAT |
||
|
05.10.23 |
DinodasRAT uses TEA to decrypt some of its strings, as well as to encrypt/decrypt data sent to, or received from, its C&C server. |
RAT |
||
|
05.10.23 |
SeroXen is a fileless Remote Access Trojan (RAT) that excels in evading detection through both static and dynamic analysis methods |
RAT |
||
|
30.09.23 |
Proofpoint identified a new malware called ZenRAT being distributed via fake installation packages of the password manager Bitwarden. |
RAT |
||
|
30.09.23 |
Gh0stCringe RAT Being Distributed to Vulnerable Database Servers |
RAT |
||
|
30.09.23 |
China Chopper is a Web Shell hosted on Web servers to provide access
back into an enterprise network that does not rely on an infected |
RAT |
||
|
22.09.23 |
Attack Activities by Quasar Family |
RAT |
||
|
20.09.23 |
In March 23, Proofpoint identified a new malware we dubbed ValleyRAT. |
RAT |
||
|
19.09.23 |
Malware with wide range of capabilities ranging from RAT to ransomware. |
RAT |
||
|
19.09.23 |
According to PCrisk, CapraRAT is the name of an Android remote access
trojan (RAT), possibly a modified version of another |
RAT |
||
|
06.09.23 |
Analysis of Andariel’s New Attack Activities |
RAT |
||
|
06.09.23 |
GoatRAT Attacks Automated Payment Systems |
RAT |
||
|
02.09.23 |
ANALYSIS OF NOVEL RAT DISCOVERED DUBBED “SUPERBEAR”. THE RAT HAS BEEN
FOUND TARGETING JOURNALIST AND DEPLOYED |
RAT |
||
|
25.08.23 |
Lazarus Group's infrastructure reuse leads to discovery of new malware |
RAT |
||
|
25.08.23 |
QuiteRAT is a simple remote access trojan written with the help of Qt libraries. |
RAT |
||
|
23.08.23 |
‘Malware-as-a-service’ has been around for some time, however of late,
it has become increasingly convenient for cybercriminals to |
RAT |
||
|
23.08.23 |
The malware has been released on github at https://github.com/EVLF/Cypher-Rat-Source-Code |
RAT |
||
|
22.08.23 |
RSA describes PlugX as a RAT (Remote Access Trojan) malware family that is around since 2008 and is used as a backdoor to control the victim's machine fully. |
RAT |
||
|
21.08.23 |
In March 23, Lumen Black Lotus Labs reported on a complex campaign called “HiatusRAT” that infected over 100 edge networking devices globally. |
RAT |
||
|
19.08.23 |
Gigabud is the name of an Android Remote Access Trojan (RAT) Android
that can record the victim's screen and steal banking |
RAT |
||
|
14.08.23 |
A new threat has emerged in the realm of cybersecurity, referred to as QwixxRAT. Both businesses and individual users are at risk, as this Trojan silently infiltrates devices, casting a wide net of data extraction. |
RAT |
||
|
14.08.23 |
According to Zscaler, JanelaRAT is a heavily modified variant of BX RAT. |
RAT |
||
|
12.08.23 |
Malware with wide range of capabilities ranging from RAT to ransomware. |
RAT |
||
|
08.08.23 |
Multiple malicious OpenBullet configuration files are being shared
within these communities, resulting in the installation of a |
RAT |
||
|
03.08.23 |
Proofpoint describes Phorpiex/Trik as a SDBot fork (thus IRC-based) that has been used to distribute GandCrab, Pushdo, Pony, and coinminers. |
RAT |
||
|
03.08.23 |
Malicious Macros Adapt to Use Microsoft Publisher to Push Ekipa RAT |
RAT |
||
|
31.07.23 |
AVrecon is a Linux-based Remote Access Trojan (RAT) targeting small-office/home-office (SOHO) routers and other ARM-embedded devices. |
RAT |
||
|
26.07.23 |
Pupy is the name of an open-source Remote Administration Trojan (RAT) written in Python. |
RAT |
||
|
22.07.23 |
DarkComet is one of the most famous RATs, developed by Jean-Pierre Lesueur in 2008. |
RAT |
||
|
22.07.23 |
HotRat: The Risks of Illegal Software Downloads and Hidden AutoHotkey Script Within |
RAT |
||
|
18.07.23 |
Deed RAT, a piece of remote access trojan malware, has seen a resurgence in use over the recent weeks. |
RAT |
||
|
14.07.23 |
Kroll has identified a fully featured information stealer and remote
access tool (RAT) in the Python Package Index |
RAT |
||
|
11.07.23 |
Github Repository with source code for Pandora hVNC |
RAT |
||
|
10.07.23 |
Unit 42 observed threat actor Tropical Scorpius using this RAT in operations where also Cuba ransomware was deployed. |
RAT |
||
|
07.07.23 |
According to ProofPoint, FlawedGrace is written in C++ and can be categorized as a Remote Access Trojan (RAT) |
RAT |
||
|
07.07.23 |
Unit 42 observed threat actor Tropical Scorpius using this RAT in operations where also Cuba ransomware was deployed. |
RAT |
||
|
07.07.23 |
VenomRAT - new, hackforums grade, reincarnation of QuassarRAT |
RAT |
||
|
30.06.23 |
Lazarus and the tale of three RATs |
RAT |
||
|
30.06.23 |
Emulating the Highly Sophisticated North Korean Adversary Lazarus Group |
RAT |
||
|
30.06.23 |
Dtrack is a Remote Administration Tool (RAT) developed by the Lazarus group. |
RAT |
||
|
30.06.23 |
Andariel, a part of the notorious Lazarus group, is known for its use of the DTrack malware and Maui ransomware in mid-22 |
RAT |
||
|
30.06.23 |
This is the third installment of a three-part technical analysis of the fully undetectable (FUD) obfuscation engine BatCloak and SeroXen malware. |
RAT |
||
|
22.06.23 |
Zscaler ThreatLabz researchers observed multiple threat campaigns utilizing the Snip3 crypter, a multi-stage remote access trojan (RAT). |
RAT |
||
|
13.06.23 |
The first messages about VenomRAT started to appear in June 2020. |
RAT |
||
|
13.06.23 |
DCRat is a typical RAT that has been around since at least June 2019. |
RAT |
||
|
31.05.23 |
Unit 42 observed threat actor Tropical Scorpius using this RAT in operations where also Cuba ransomware was deployed. |
RAT |
||
|
19.05.23 |
ReversingLabs researchers discovered two malicious packages that
contained TurkoRat, an open source infostealer that lurked on n |
RAT |
||
|
18.05.23 |
Android Spyware is one of the most common kinds of malware used by attackers to gain access to personal data and carry out fraud operations. |
RAT |
||
|
12.05.23 |
AllaKore is a simple Remote Access Tool written in Delphi, first observed in 2015 but still in early stages of development. |
RAT |
||
|
12.05.23 |
Action RAT is a remote access tool written in Delphi that has been used
by SideCopy since at least December 2021 against Indian and |
RAT |
||
|
06.05.23 |
goatRat is the name of a remote access trojan (RAT) - a malicious app that allows attackers to take control of an Android device. |
RAT |
||
|
05.05.23 |
GravityRAT malware takes your system's temperature |
RAT |
||
|
05.05.23 |
It is a backdoor commonly distributed as an encoded binary file downloaded and decrypted by shellcode following the exploitation of weaponized documents. |
RAT |
||
|
28.04.23 |
Targets of Interest - Russian Organizations Increasingly Under Attack By Chinese APTs |
RAT |
||
|
28.04.23 |
Simple yet powerful RAT for Windows machines. This project is simple and easy to understand, |
RAT |
||
|
26.04.23 |
RAT |
|||
|
26.04.23 |
Information stealer which uses AutoIT for wrapping. |
RAT |
||
|
20.04.23 |
Unit 42 observed threat actor Tropical Scorpius using this RAT in operations where also Cuba ransomware was deployed. |
RAT |
||
|
14.04.23 |
Love scam or espionage? Transparent Tribe lures Indian and Pakistani officials |
RAT |
||
|
14.04.23 |
According to SentinelOne, this RAT can gather and transmit a defined set
of system features, create/terminate/manipulate processes and files, a |
RAT |
||
|
08.04.23 |
Malicious Macros Adapt to Use Microsoft Publisher to Push Ekipa RAT |
RAT |
||
|
08.04.23 |
ViperRAT is an active, advanced persistent threat (APT) that
sophisticated threat actors are actively using to target and spy on the
Israeli |
RAT |
||
|
6.4.23 |
Pupy rat is an open source tool for cross-platform remote administration
(Windows, Linux, OSX, Android are supported as “clients”) |
RAT |
||
|
3.4.23 |
Action RAT is a remote access tool written in Delphi that has been used
by SideCopy since at least December 2021 against Indian and |
RAT |
||
|
23.03.23 |
DEMYSTIFYING NEW VIRTUALIZED .NET INJECTOR USED IN THE WILD |
RAT |
||
|
10.03.23 |
Netwire is a RAT, its functionality seems focused on password stealing and keylogging, but includes remote control capabilities as well. |
RAT |
||
|
10.03.23 |
Xenomorph is a Android Banking RAT developed by the Hadoken.Security actor. |
RAT |
||
|
07.03.23 |
CrimsonRAT is a remote access Trojan used to take remote control of
infected systems and steal data. We know this particular RAT is used by
the |
RAT |
||
|
07.03.23 |
Most likely active since July
22, the campaign has distributed
CapraRAT backdoors through at least two similar websites, while
representing them |
RAT |
||
|
06.03.23 |
According to Black Lotus Labs, ZuoRAT is a MIPS file compiled for SOHO
routers that can enumerate a host and internal LAN, capture packets
being |
RAT |
||
|
06.03.23 |
Just nine months after discovering ZuoRAT – a novel malware targeting small office/home office (SOHO) routers – Lumen Black Lotus Labs® |
RAT |
||
|
02.03.23 |
HyperBro is a RAT that has been observed to target primarily within the gambling industries, though it has been spotted in other places as well. |
RAT |
||
|
28.02.23 |
According to Bitdefender, BitRAT is a notorious remote access trojan
(RAT) marketed on underground cybercriminal web markets and forums. Its
price tag |
RAT |
||
|
27.02.23 |
RSA describes PlugX as a RAT (Remote Access Trojan) malware family that is around since 2008 and is used as a backdoor to control the victim's machine fully. |
RAT |
||
|
23.02.23 |
New Ransomware Groups On The Rise: “RedAlert,” LILITH And 0mega Leading A Wave Of Ransomware Campaigns |
RAT |
||
|
21.02.23 |
APT SideCopy Targeting Indian Government Entities - Analysis of the new version of ReverseRAT |
RAT |
||
|
18.02.23 |
Operation Silent Watch: Desktop Surveillance in Azerbaijan and Armenia |
RAT |
||
|
18.02.23 |
'Purple Fox' Hackers Spotted Using New Variant of FatalRAT in Recent Malware Attacks |
RAT |
||
|
15.02.23 |
The RedEyes group is known to steal personal PC information as well as mobile phone data targeting specific individuals, not companies. |
RAT |
||
|
11.02.23 |
According to Security Ninja, Gh0st RAT (Remote Access Terminal) is a
trojan “Remote Access Tool” used on Windows platforms, and has been used
to |
RAT |
||
|
11.02.23 |
CloudEyE (initially named GuLoader) is a small VB5/6 downloader. It
typically downloads RATs/Stealers, such as Agent Tesla, Arkei/Vidar,
Formbook, Lokibot, |
RAT |
||
|
08.02.23 |
Remcos (acronym of Remote Control & Surveillance Software) is a Remote Access Software used to remotely control computers. |
RAT |
||
|
28.01.23 |
Orcus has been advertised as a Remote Administration Tool (RAT) since early 2016. It has all the features that would be expected from a RAT and probably more. |
RAT |
||
|
28.01.23 |
Attacks Evade Detection with SparkRAT and Golang Source Code Interpretation |
RAT |
||
|
28.01.23 |
CageyChameleon Malware is a VBS-based backdoor which has the capability
to enumerate the list of running processes and check for the presence
|
RAT |
||
|
27.01.23 |
StrifeWater RAT: Iranian APT Moses Staff Adds New Trojan to Ransomware Operations |
RAT |
||
|
27.01.23 |
According to Securonix, this malware exhibits remote access trojan (RAT) behavior, allowing for control of and persistence on the affected host. |
RAT |
||
|
20.01.23 |
We discovered an active campaign ongoing since at least mid-22 which
uses Middle Eastern geopolitical-themed lures to distribute NjRAT (also
known as Bladabindi) |
RAT |
||
|
14.01.23 |
Let’s take a look at a recent sample of the Java-based malware known as STRRAT. |
RAT |
||
|
09.01.23 |
A new malware campaign has been observed using sensitive information stolen from a bank as a lure in phishing emails to drop a remote access trojan called BitRAT. |
RAT |
||
|
28.06.22 |
A never-before-seen remote access trojan dubbed ZuoRAT has been singling
out small office/home office (SOHO) routers as part of a sophisticated
campaign |
RAT |
||
|
25.06.22 |
Following recently published research detailing the group’s TTPs
including their main tools “PyDcrypt” and “DCSrv”, the Cybereason
Nocturnus team |
RAT |
||
|
14.06.22 |
Warzone aims to be the Remote Access Trojan (RAT) of choice for aspiring miscreants on a budget. |
RAT |
||
|
14.06.22 |
Arkei Infostealer Expands Reach Using SmokeLoader to Target Crypto Wallets and MFA |
RAT |
||
|
14.06.22 |
PureCrypter has been growing in popularity with a number of information stealers and remote access trojans (RATs) being deployed by it. |
RAT |
||
|
12.05.22 |
RAT |
|||
|
12.05.22 |
The newly identified Nerbian RAT leverages multiple anti-analysis components spread across several stages, including multiple open-source libraries. |
RAT |
||
|
10.05.22 |
DCRat (also known as DarkCrystal RAT) is a commercial Russian backdoor that was first released in 2018, before being redesigned and relaunched a year later. |
RAT |
||
|
08.05.22 |
Nanocore is a Remote Access Tool used to steal credentials and to spy on
cameras. It as been used for a while by numerous criminal actors as well
as |
RAT |
||
|
08.05.22 |
Remcos (acronym of Remote Control & Surveillance Software) is a Remote
Access Software used to remotely control computers.Remcos, |
RAT |
||
|
02.04.22 |
RAT |
|||
|
02.04.22 |
RAT |
|||
|
02.04.22 |
RAT |
|||
|
28.03.22 |
RAT |