Ratel Master is a suspected advanced persistent threat cluster associated with intrusions against organizations in Japan. It has been linked to the RatelS backdoor and related loader components, and shows strong technical overlap with the GroundPeony cluster through shared use of Mofu Loader, DLL side-loading patterns, and closely matching second-stage shellcode logic. Reported overlaps include use of the same legitimate application for side-loading, execution of decryption logic through VerQueryValueW, the same API hashing approach, and the same custom XOR-plus-LZNT1 payload decoding pattern. Ratel Master activity also shows implementation-level similarities with Earth Estries, also known as FamousSparrow, particularly between the RatelS and HemiGate malware families. These similarities include related HTTP request construction, proxy handling, authentication logic, keylogging-related conventions, configuration structure, and use of RC4-protected payloads, although the first-stage loaders differ. Prior reporting has also noted implementation similarities between RatelS and PlugX. The available evidence supports assessment of a cooperative or code-sharing relationship among Ratel Master, GroundPeony, and Earth Estries rather than definitive proof that they are the same actor. Observed capabilities associated with Ratel Master tooling include DLL side-loading for execution, in-memory loading of payloads, encrypted configuration and payload handling, command execution through backdoor functionality, and keylogging-related behavior.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
8 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
APT activity targeting organizations in Japan. The content associates Ratel Master with RatelS and Mofu Loader, and highlights strong loader and payload similarities with GroundPeony as well as implementation similarities between RatelS and HemiGate/PlugX.
Named cluster/tooling relationship discussed as sharing Mofu Loader-related components and shellcode/decryption logic with GroundPeony and associated with RatelS activity.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.