SparkRAT is an open-source, Go-based cross-platform remote access trojan used as a backdoor in multiple intrusion sets since at least 2023. It supports Windows, Linux, and macOS and is designed to provide interactive remote control of compromised hosts, including command execution, file upload and download, host fingerprinting, process and system manipulation, and information theft. Its command-and-control communications use WebSocket, and reporting has also noted an automatic upgrade mechanism in some builds. SparkRAT has been observed both as a standalone payload and delivered through companion loaders, including LESLIELOADER, and operators have used per-target customized builds in some campaigns.
SparkRAT is strongly associated with the DragonSpark activity cluster, where it was used alongside webshells, privilege-escalation tools, shellcode loaders, and Meterpreter-enabling malware during opportunistic intrusions against internet-exposed servers in East Asia. It has also appeared in exploitation chains involving public-facing enterprise software and remote access appliances, including TeamCity and BeyondTrust compromises, where it was deployed after initial remote code execution to establish persistent access and support reconnaissance, lateral activity, and data theft. Additional reporting links SparkRAT to broader Chinese-linked or Asia-focused operations, including Webworm-related tooling overlap, RedNovember activity using LESLIELOADER to load SparkRAT, and TGR-STA-1030 operations that employed SparkRAT among several command-and-control frameworks.
Although occasionally mislabeled as an infostealer, the high-confidence characterization is a remote access trojan/backdoor. Its operational role in observed campaigns is post-compromise remote control rather than initial delivery, and it is commonly paired with other offensive tooling such as Cobalt Strike, Sliver, Havoc, VShell, webshells, and tunneling utilities. Targeting has included government, critical infrastructure, technology, healthcare, legal, education, and other enterprise environments, especially where attackers gained access through exploitation of exposed services or through loader-based deployment.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
APT29 (Cozy Bear) exploited CVE-2024-27198 in real-world campaigns.
The vulnerability, tracked as CVE-2026-1731, is an operating system command injection flaw that also impacts some older versions of BeyondTrust Privileged Remote Access. The flaw allows an attacker to execute arbitrary commands on a server without the need for credentials or any user interaction. | A critical vulnerability in BeyondTrust Remote Support is facing an increase in threat activity, with hackers deploying SparkRAT and vShell backdoors and using remote management tools to conduct reconnaissance...
ClearSky Cyber Security has uncovered a new zero-day vulnerability, CVE-2024-43451, actively exploited in the wild, targeting Windows systems primarily in Ukraine. This flaw enables attackers to exploit URL files for malicious activity by performing actions as simple as a single right-click.
8 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Sandbox family search for family:sparkrat . Returned a per-victim SparkRAT sibling submitted independently to the sandbox. Its ldflags COMMIT differs from the case sample. Confirms the operator uses per-target SparkRAT builds.
The initial analysis showed that the ZIP files downloaded were installing SparkRAT on some systems, while later variations utilized Redline Stealer.
...Leslieloader that downloads a backdoor dubbed SparkRAT. The Go variants are compliant with Windows, Linux and OSX. They support file upload and download, system fingerprinting and direct command-line interaction with infected hosts.
"...including CurlBack, SparkRAT, AresRAT, Xeno RAT, AllaKore, and ReverseRAT."
The attacks are characterized by the use of the little known open source SparkRAT and malware that attempts to evade detection through Golang source code interpretation.
...UNK_ColtCentury... likely an attempt to deploy the SparkRAT backdoor.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
A critical vulnerability in BeyondTrust Remote Support is facing an increase in threat activity ... Multiple BeyondTrust Remote Support users have been confirmed targets ... The flaw allows an attacker to execute arbitrary commands on a server without the need for credentials or any user interaction.
This version supports 26 commands... including execution of arbitrary Windows system and PowerShell commands.
This version supports 26 commands that implement a wide range of functionalities: Command execution: including execution of arbitrary Windows system and PowerShell commands.
Information theft: including exfiltration of platform information... and process and file enumeration.
"Among the tools put to use by the threat actor are command-and-control (C2) frameworks... Cobalt Strike, VShell, Havoc, Sliver, and SparkRAT"
SparkRAT uses the WebSocket protocol to communicate with the C2 server and features an upgrade system.
11 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
33 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote access trojan/backdoor deployed following exploitation of TeamCity vulnerabilities.
Remote access trojan observed in exploitation activity targeting a BeyondTrust critical vulnerability (CVE-2026-1731).
Remote access trojan observed in exploitation activity against BeyondTrust (CVE-2026-1731) per the content.
Remote access trojan used to provide interactive remote control of compromised hosts as part of post-exploitation activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.