HZ Rat is a remote access trojan and backdoor family active since at least 2020, with campaigns primarily oriented toward victims in China. It has been observed on Windows and later on macOS, where a variant targeted users of DingTalk and WeChat. The malware provides attackers with remote control over infected systems and supports command execution, file transfer, file upload, and PowerShell-based tasking on Windows; the macOS variant mirrors core backdoor functionality while using shell-script-based payload handling.
On Windows, HZ Rat has been delivered through at least two established infection chains: malicious RTF lure documents exploiting CVE-2017-11882, and self-extracting archives masquerading as legitimate software. In the archive-based chain, a script launches the backdoor and then opens a decoy application to reduce suspicion. The malware has also been described as being delivered as a payload from a downloader. Multiple versions and custom packers have been identified, including Base64- and AES-based variants, indicating sustained development and operational reuse.
HZ Rat communicates with command-and-control infrastructure using a custom XOR-encrypted protocol and iterates through embedded server lists to obtain tasking. Observed commands and server-side tasking show a strong emphasis on reconnaissance and theft of user and operator data, including messaging-app artifacts, browser-stored information, email-client data, developer and administration credentials, and other locally stored files of operational interest. Samples have also used mutex-based execution control, and some infrastructure and tooling characteristics have overlapped with Cobalt Strike-related activity.
The macOS variant reported in 2024 retained the family’s backdoor role and was associated with targeted activity against DingTalk and WeChat users. Its use of local-network command-and-control addressing suggested possible targeted deployment and lateral movement within victim environments rather than broad indiscriminate distribution.
Overall, HZ Rat is best characterized as a cross-platform backdoor/RAT used in targeted intrusion activity, with delivery methods combining exploit-based initial access and trojanized software lures, and with post-compromise objectives centered on remote control, reconnaissance, credential collection, and data theft.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Once opened, the document writes HZ Rat to disk as default.exe and executes it with an Equation Editor exploit (CVE-2017–11882) hidden in the document and triggered after opening the document. | Turns out we found HZ Rat — a lesser known Trojan... Therefore, the malware we analyse in the this article can be identified as “Backdoor.HZRat!1.DB91 (CLASSIC)”, defining the name of the malware as “HZ Rat”.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
Once opened, the document writes HZ Rat to disk as default.exe and executes it with an Equation Editor exploit (CVE-2017–11882) hidden in the document and triggered after opening the document.
290 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote access trojan providing full remote control of infected macOS systems; commonly delivered by a downloader.
Remote access trojan/backdoor targeting macOS and Windows, used for lateral movement and targeting messaging app users.
A simple backdoor/RAT used as an initial access tool. It iterates through a list of C2 servers, connects using a custom XOR-encrypted protocol and handshake, and executes commands from the server. Reported capabilities include executing PowerShell commands/scripts, writing files to disk, uploading files to C2, and limited ping functionality. The campaign also used custom packers and focused on credential theft and system reconnaissance.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.