RattyRAT is a Java-based remote access trojan associated with the financially motivated Scattered Spider (UNC3944) cybercrime group. It has been used to establish persistent, stealthy access to compromised environments and to conduct internal reconnaissance. Scattered Spider has deployed RattyRAT in intrusions against large enterprises, including alongside data-extortion activity and ransomware operations. RattyRAT has also been observed in tax-themed malware-delivery campaigns.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
CISA has confirmed the group is using DragonForce ransomware to encrypt victims’ ESXi environments, alongside past use of ALPHV/BlackCat and RansomHub, and custom tools like the RattyRAT remote access trojan to maintain stealthy, persistent footholds.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
eSentire has observed a substantial increase in malware being delivered through tax-themed phishing emails. Cybercriminals are exploiting the urgency and importance of tax-related communications to trick individuals into opening malicious email links, leading to malware infections.
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote-access trojan used by Scattered Spider to maintain stealthy and persistent access in compromised environments.
Java-based remote access trojan used for persistent, stealthy remote access and internal reconnaissance.
Remote access trojan used to establish persistence, maintain stealth, and conduct reconnaissance on compromised hosts.
A Java-based remote access trojan used for long-term stealthy access and internal reconnaissance.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.