PatoRAT is a Delphi-based backdoor/RAT reported in campaigns abusing legitimate remote monitoring and management (RMM) tools for full system takeover. AhnLab Security intelligence Center (ASEC) reported that attackers distributed LogMeIn Resolve and PDQ Connect through malicious download pages impersonating legitimate software and brands including Notepad++, 7-Zip, Telegram, ChatGPT, and OpenAI, then used those RMM tools to execute PowerShell commands and install PatoRAT. The malware was specifically noted as being installed via both LogMeIn Resolve and PDQ Connect. The reporting characterizes the resulting compromise as enabling full system takeover. The associated activity reflects abuse of legitimate RMM software to evade traditional security controls because such tools are signed, legitimate remote administration utilities. No specific threat actor attribution, victim sector targeting, or malware-specific indicators of compromise for PatoRAT were provided in the content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor/RAT payload installed via abused RMM tools (LogMeIn Resolve and PDQ Connect) after attackers gain execution, enabling remote control of the victim system.
A Delphi-based remote access backdoor/RAT used to hijack LogMeIn Resolve and PDQ Connect remote management tools to achieve full system takeover.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.