A remote access trojan (RAT) is malware that provides an attacker with covert remote control over an infected system. RATs commonly support interactive command execution, system profiling, arbitrary code execution, file transfer, credential harvesting, persistence, and data exfiltration, enabling both espionage and broader post-compromise operations. They are frequently used as full-featured backdoors after initial compromise and can facilitate follow-on actions such as lateral movement, extortion, or deployment of additional malware.
Recent observed use cases include software supply-chain compromises, social-engineering campaigns, and scam-driven malware delivery. In one documented npm supply-chain campaign tracked as ChainVeil and attributed to the actor SuccessKey, malicious JavaScript packages executed on import rather than installation and ultimately delivered a RAT through a resilient multi-stage command-and-control architecture that used blockchain services for payload resolution and fallback retrieval. That payload supported reverse-shell access, credential harvesting, file exfiltration, arbitrary JavaScript execution, background process spawning, process termination, and persistence through hidden shell-configuration modification, while also incorporating anti-analysis checks. RAT delivery has also been reported in other npm package compromises involving obfuscated payloads.
RATs are also distributed through social-engineering operations, including fraudulent support tickets targeting help-desk personnel, fake single sign-on lures, and online job scams in which malware is disguised as interview software or application materials. These campaigns aim to compromise employee or personal devices, steal credentials and sensitive data, and establish persistent access that can later be leveraged against enterprise environments. In operational technology and transportation contexts, suspected RAT infections have raised concern because remote access on poorly segmented systems can expose sensitive onboard or industrial functions.
RATs primarily target general-purpose computing environments and are especially prevalent on Windows, macOS, and Linux systems, though specific families vary widely in implementation and tradecraft. As a category, RATs remain a staple tool for cybercriminal and state-linked intrusion activity because they combine persistence, operator interactivity, and flexible post-exploitation capability in a single malware class.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
It uses an unprecedented 4-tier blockchain-based Command and Control ( C2 ) infrastructure spanning three blockchains (Tron, Aptos, Binance Smart Chain) to deliver a full-featured Remote Access Trojan (RAT) with reverse shell, credential harvesting, file exfiltration, and persistent backdoor injection.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
When the axios HTTP client library was compromised, attackers pushed two poisoned releases that dropped a remote-access Trojan on every machine that ran a fresh install during a roughly three-hour window.
A separate supply-chain attack on the widely used Axios npm package occurred within hours of the leak, injecting a remote-access trojan into versions 1.14.1 and 0.30.4.
VentureBeat reported that anyone who installed or updated Claude Code via npm on March 31 between 00:21 and 03:29 UTC may have pulled in the compromised dependency.
The threat actor also used our models to generate code for obfuscation and “crypter” patterns, such as inserting padding instructions and junk sequences
The package impersonated an installer for OpenClaw... The campaign combined brand impersonation with malicious package delivery, using a familiar project name to increase the odds of installation by developers or users seeking OpenClaw tooling.
VentureBeat reported that anyone who installed or updated Claude Code via npm on March 31 between 00:21 and 03:29 UTC may have pulled in the compromised dependency.
Step 2 — Poison it. Add something malicious. Usually this hides in a postinstall script — a feature that lets packages run code automatically the moment you install them, with no confirmation prompt.
typical operator use of the model involved eliciting building-block code, such as converting compiled executables into shellcode, designing in-memory loaders | Specifically, they used ChatGPT to generate and iterate on working code and deployment guidance for in-memory execution and shellcode loaders
9 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An obfuscated remote access trojan was shipped via compromised npm packages @joyfill/components and @joyfill/layouts as part of a supply-chain compromise.
Final payload delivered by the ChainVeil npm campaign. It provides reverse shell access, steals credentials, exfiltrates files, fingerprints hosts, and injects persistence into shell startup files.
A Remote Access Trojan (RAT) is a type of malware that allows attackers to remotely control infected systems, potentially providing access to sensitive ship functions including navigation and operating systems.
Remote Access Trojans (RATs) are used to provide attackers with persistent, covert access to compromised endpoints, allowing them to steal data, move laterally, and further compromise the organization.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.