WogRAT is a backdoor malware, reportedly short for "WingsOfGod," that can collect system information and execute arbitrary commands received from a remote C2 server. The content states it was developed by referencing routines from the open-source malware Tiny SHell. It has both Windows and Linux variants, and ELF-based samples were observed at malware distribution infrastructure, indicating Linux targeting in addition to Windows. In the reported campaigns, WogRAT was found alongside MeshAgent, SuperShell, web shells, and other public offensive tools in attacks against South Korean web servers. The intrusion chain described in the content involved exploitation of file upload vulnerabilities to deploy ASP/ASPX web shells on IIS servers, followed by reconnaissance, privilege escalation, credential dumping, and lateral movement. The same campaign used tools such as Fscan, Ladon/PowerLadon, Network Password Dump, and WMIExec, with attackers attempting to spread to additional Windows and Linux systems and potentially target MS-SQL Server. The content says WogRAT's C2 server address matched infrastructure used in earlier attacks involving aNotepad, suggesting the same attacker was likely responsible for both operations. Reporting cited in the content assesses the operators as likely Chinese-speaking actors, though attribution is complicated by their use of public tools. High-confidence infrastructure and IOC details directly mentioned include linuxwork[.]net and 139[.]180[.]142[.]127, as well as unspecified MD5 hashes provided in the source reporting.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
WogRAT is a backdoor and remote access trojan capable of collecting system information and executing arbitrary commands from a remote server.
WogRAT is a cross-platform backdoor (Windows and Linux) that provides remote access and control to attackers. It is based on routines from Tiny SHell and has been used in attacks exploiting web server vulnerabilities and free online platforms for distribution.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.