Ratty RAT is a Java-based remote access trojan used to provide persistent remote control over compromised systems. It is commonly distributed as a JAR archive and can run on Windows, Linux, and macOS systems where the Java Runtime Environment is installed. Documented capabilities include remote command execution, file access, keystroke logging, and activation of webcam and microphone functions, making it suitable for surveillance and theft of sensitive information.
Observed delivery has included phishing campaigns targeting organizations in Spain, Italy, and Portugal. In one reported intrusion chain, attackers used invoice-themed lures delivered by email, with staged redirection through legitimate file-sharing and tunneling services and geo-fenced cloaking to reduce exposure to researchers and automated defenses before delivering the malicious Java archive. The malware has also been identified among commodity tools used by the financially motivated threat actor Scattered Spider, alongside other stealers and remote access utilities, to support intrusion activity and collection of sensitive data.
Ratty RAT is primarily associated with post-compromise remote access and operator-controlled surveillance on endpoints rather than autonomous propagation. Its cross-platform Java implementation and use in socially engineered delivery chains make it a flexible tool for targeting organizations across multiple desktop operating systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Kritická zraniteľnosť CVE-2025-2611 spočíva v nedostatočnom overovaní vstupov a vzdialený neautentifikovaný útočník by ich mohol zneužiť na vzdialenú injekciu shellových príkazov do relačných cookies BROADCAST, ktoré sa vykonajú na serveri. To môže viesť ku schopnosti vzdialene vykonávať kód bez autentifikácie.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"...malware tools like ... and Ratty RAT to facilitate remote access and gather sensitive information"
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote access trojan distributed via an email campaign targeting Spain, Italy, and Portugal; mentioned here only as an association for overlapping IOC.
Java-based remote access trojan used to provide remote control of infected systems; mentioned here due to infrastructure/indicator overlap (localto[.]net and 143.47.53[.]106) with exploitation activity against ICTBroadcast.
Remote access trojan used to facilitate remote access and gather sensitive information.
Java-based remote access trojan typically delivered as a .jar (and sometimes packaged as an MSI) that enables remote command execution, keystroke logging, screenshot capture, access to files, and control of peripherals such as webcam/microphone on systems with JRE installed.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.