Rogue Raticate, also referred to as RATicate, is a financially motivated cybercrime threat actor associated with phishing and fake-update infection chains that culminate in the delivery of NetSupport RAT. The group has been linked to email-based phishing activity using decoy documents and malicious links, as well as browser-update lures delivered through compromised websites. Observed operations rely on social engineering to convince victims to retrieve and execute follow-on content that installs remote access tooling. Rogue Raticate has been associated with campaigns that use Traffic Distribution Systems to route victims through staged delivery infrastructure before serving malware. In related activity, compromised WordPress sites have been used to inject malicious JavaScript that replaces legitimate page content with convincing browser-specific update prompts. Delivery mechanisms observed in these clusters include compressed archives, Internet shortcut files, obfuscated HTA launchers, and PowerShell-based retrieval of final payloads. The actor’s tradecraft emphasizes layered obfuscation, abuse of legitimate administration and scripting functionality, and multi-stage execution chains designed to hinder analysis and increase infection success. The principal malware family tied to Rogue Raticate in the available reporting is NetSupport RAT, a legitimate remote support tool frequently abused by threat actors for unauthorized access, command execution, and follow-on payload delivery. Techniques associated with these campaigns include phishing, drive-by compromise via hacked websites, malicious script execution, command shell and PowerShell abuse, system binary proxy execution, registry modification, and command-and-control over application-layer protocols. Some observed chains also include privilege-escalation or defense-evasion steps such as encoded scripting and user account control bypass. Rogue Raticate should be tracked as a cybercrime actor focused on initial access and remote access deployment rather than as a confirmed nation-state intrusion set. The name has been used in connection with fake browser update and phishing campaigns that resemble broader criminal malware-delivery ecosystems, but the available information does not support stronger attribution beyond financially motivated malicious activity. Known alias: RATicate.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cybercrime group attributed to an email phishing campaign using PDF decoys and a TDS to deliver NetSupport RAT.
Named activity cluster/campaign involving fake-update lures delivered via URL shortcuts, using compromised WordPress sites and WebDAV-hosted payload staging to ultimately load NetSupport RAT.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.