CHAOS RAT, also known as the CHAOS Remote Administrative Tool, is an open-source, Go-based remote access trojan targeting Linux and Windows systems. It communicates with a configured command-and-control server using token-based authorization and provides operators with remote shell access, host and operating-system information collection, file browsing, upload, download, and deletion, screenshot capture, and host restart or shutdown functions. Observed Linux deployments have included cryptojacking campaigns targeting cloud instances and supply-chain compromises involving trojanized Arch User Repository and npm packages. In those incidents, CHAOS RAT was installed as a secondary payload or used as the basis for a Linux backdoor with system-service persistence, Tor-mediated command-and-control, SSH-key theft and lateral propagation. Its functionality gives operators broad post-compromise control and supports collection and removal of data from compromised hosts.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Cross Site Scripting vulnerability in tiagorlampert CHAOS v.5.0.1 allows a remote attacker to escalate privileges via the sendCommandHandler function in the handler.go component.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
The malware achieves its persistence by altering /etc/crontab file, a UNIX task scheduler that, in this case, downloads itself every 10 minutes from Pastebin.
When running, the RAT client connects to the C&C server via its address, and default port, using a JSON Web Token (JTW) for authorization.
Le backdoor communique via Tor (socks5://127.0.0.1:9050) vers un service caché .onion.
This was followed by routines for persistence and payload execution, which in most cases is a Monero (XMR) cryptocurrency miner.
the initial phase saw attackers trying to kill off competing malware, security products, and other cloud middleware.
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Outil open-source de remote-access trojan dont le client sert de base au backdoor systemd-fontd déployé dans cette campagne.
Referenced as an example of a malicious upload in AUR to illustrate software verification risks.
Open-source RAT variant used in attacks against Windows and Linux, reportedly distributed via fake network tool downloads.
Remote access trojan delivered via malicious Arch Linux AUR packages, providing remote control capability on infected systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.