Chaos RAT is an open-source, Go-based remote access trojan that targets Linux and Windows systems and provides broad post-compromise control of infected hosts. It has been observed both as a standalone RAT and as a secondary payload in other intrusion chains, including Linux cloud cryptojacking activity and malicious software package distribution. Reported capabilities include establishing an authenticated command-and-control session, collecting host and operating system information, executing reverse shells, transferring files in both directions, deleting files, browsing the file system, capturing screenshots, opening URLs, and restarting or shutting down the compromised machine. In Linux-focused intrusions, it has been deployed alongside cryptocurrency-mining tooling and persistence mechanisms, expanding an otherwise commodity mining operation into a more flexible hands-on-keyboard compromise. Chaos RAT has also been distributed through malicious Arch Linux AUR packages, demonstrating its use in software supply-chain style delivery against developer and Linux user ecosystems. The malware is notable for embedding command-and-control configuration and an authorization token at build time, reflecting its origin as a customizable open-source RAT rather than a tightly controlled closed malware family.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
When running, the RAT client connects to the C&C server via its address, and default port, using a JSON Web Token (JTW) for authorization.
This was followed by routines for persistence and payload execution, which in most cases is a Monero (XMR) cryptocurrency miner.
the initial phase saw attackers trying to kill off competing malware, security products, and other cloud middleware.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Open-source RAT variant used in attacks against Windows and Linux, reportedly distributed via fake network tool downloads.
Remote access trojan delivered via malicious Arch Linux AUR packages, providing remote control capability on infected systems.
Go-based cross-platform remote access trojan (Windows and Linux).
Go-compiled Linux RAT used alongside a cryptojacking campaign. It connects to a separate C2 server using a hardcoded address and token, sends infected-host details, and supports reverse shell, file download/upload/delete, screenshots, file explorer access, OS information gathering, reboot/shutdown, and opening URLs.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.