oRAT is a Go-based remote access trojan targeting Linux systems, with a documented macOS variant. It provides remote administration of compromised hosts, including command and shell execution, file upload and download, proxying and tunneling, port scanning, and embedded SSH/SFTP functionality. Linux variants can disable SELinux, establish persistence through a system service masquerading as a firewall-related component, masquerade their process, and conceal process information. A macOS variant supports shell access, file transfer, proxy connections, port scanning, screenshot capture, archive operations, and self-deletion; it has been distributed in an unsigned disk image impersonating Bitget software that executes a payload through an installer preinstallation script. oRAT has been associated with Earth Berberoka-related activity and the Gambling Goblin operation, which compromised Linux web servers at Brazilian government, educational, commercial, healthcare, and media organizations. The name ORat has also been used for a distinct Windows loader associated with BRONZE PRESIDENT/Mustang Panda; that tool uses WMI event-consumer persistence and should not be conflated with the Go-based Linux and macOS oRAT RAT.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“Its toolkit includes DownPro, AlphaAgent, oRAT RAT, 3snake credential stealer, SSH brute-forcer, and reconnaissance tools.”
“oRAT can establish persistence through a service that mimics a legitimate firewall component.”
ORat — CTU researchers have only observed this basic loader tool in the context of BRONZE PRESIDENT intrusions. ORat is the name assigned by the malware author, as denoted by the program debug database string in the analyzed sample: D:\vswork\Plugin\ORat\build\Release\ORatServer\Loader.pdb.
25 distinct techniques documented for this family, organized by ATT&CK tactic.
If oRAT lacks privileges for a system-wide install, it falls back to per-user persistence through a user service and a cron entry.
“oRAT similarly establishes persistence through a service designed to resemble a normal firewall-related component.”
The tool uses the Windows Management Instrumentation (WMI) event consumer for persistence by installing a script to the system's WMI registry. For example, ORat uses a WMI event consumer to maintain its presence on a compromised host.
If oRAT lacks privileges for a system-wide install, it falls back to per-user persistence through a user service and a cron entry.
“oRAT similarly establishes persistence through a service designed to resemble a normal firewall-related component.”
The tool uses the Windows Management Instrumentation (WMI) event consumer for persistence by installing a script to the system's WMI registry. For example, ORat uses a WMI event consumer to maintain its presence on a compromised host.
“Several tools use disguises, encryption, and memory-only unpacking.”
The binary doesn’t define any Symbols, and outputting the list of Sections tells us that the file has been packed with UPX.
AlphaAgent can... hide under system-service names. oRAT can establish persistence through a service that mimics a legitimate firewall component.
Depending on the config, it will call one of orat_protocol.DialTCP, orat_protocol.DialSTCP or orat_protocol.DialSUDP to establish a connection. The TCP protocols leverage smux while the SUDP protocol leverages QUIC.
AlphaAgent primarily uses gRPC over HTTPS; oRAT multiplexes HTTP requests over TCP, TLS/TCP, or QUIC/UDP sessions.
AlphaAgent bundles a SOCKS5 proxy, yamux multiplexer, Ligolo-style relay, and a relay listener that forwards traffic upstream.
“After gaining access, the attackers can deploy additional tools through DownPro, a loader capable of retrieving payloads such as the ChUser backdoor, AlphaAgent and oRAT.”
“AlphaAgent supported remote command execution (RCE), file transfers, tunneling and host discovery, while oRAT provided remote administration.”
97 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote-access trojan in Gambling Goblin's toolkit, associated with compromised Linux servers used to proxy visitors to attacker-controlled phishing pages.
A remote-access backdoor that maintains persistence using a service disguised as a legitimate firewall-related component.
A remote-access trojan/backdoor that persists by installing a service impersonating a legitimate firewall component.
A remote-access trojan that establishes persistence by creating a service designed to resemble a legitimate firewall component.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.