P8RAT, also known as GreetCake and HEAVYPOT, is a memory-resident remote access trojan associated with Chinese espionage activity, particularly clusters linked to A41APT and frequently discussed alongside APT10/menuPass tooling. It has been observed as a payload delivered by multi-stage loaders including DESLoader and SigLoader in intrusions targeting Japanese organizations and their overseas branches, as well as in broader managed-services intrusion scenarios.
P8RAT is characterized as a fileless RAT that executes in memory and supports command-and-control driven post-compromise operations. Reported command identifiers span at least 300 through 309, indicating an actively maintained command set. The malware gathers basic host profiling data such as operating system version, hostname, and username, and performs anti-analysis checks including inspection for processes associated with virtualized or sandboxed environments. It also supports configurable sleep delays to evade automated analysis and can pad or randomize outbound command-and-control traffic with generated data to complicate network detection and protocol analysis.
Operationally, P8RAT appears in intrusion chains following compromise of internet-facing infrastructure, especially SSL-VPN appliances and other externally exposed enterprise systems. In those campaigns, attackers used loaders and DLL side-loading frameworks to establish persistence and execute payloads in memory, then leveraged tools for credential theft, lateral movement, and broader post-exploitation. P8RAT fits into this ecosystem as an in-memory access implant used after initial compromise rather than as a standalone initial-access mechanism.
The malware has been associated with enterprise targeting, including managed service environments and Japanese corporate networks. Its repeated use alongside SodaMaster, SigLoader, FYAntiLoader, Cobalt Strike, and related tooling places it within a mature espionage tradecraft set focused on stealth, memory-only execution, and long-term access.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Install malware by using Taskscheduler ... ●SigLoader ●SodaMaster ●P8RAT ●Cobalt Strike ●FYAntiLoader
10 distinct techniques documented for this family, organized by ATT&CK tactic.
Decrypt multiple PEs and shellcodes sequentially in multiple stages. Multiple algorithms are used for decryption. Finally, the payload is executed in memory.
Several entries describe malware examining running processes to determine if a debugger, sandbox, virtual environment, or analysis/security tools are present, such as AsyncRAT checking for a debugger, RogueRobin enumerating Wireshark and Sysinternals processes, and P8RAT checking for processes associated with virtual environments.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
Several entries describe malware examining running processes to determine if a debugger, sandbox, virtual environment, or analysis/security tools are present, such as AsyncRAT checking for a debugger, RogueRobin enumerating Wireshark and Sysinternals processes, and P8RAT checking for processes associated with virtual environments.
最終的に実行されるペイロード(DelfsCake)は、DLL形式で、C2サーバからデータやペイロードなどを受信して実行する機能を有します。
10 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote access trojan listed as part of the malware suite used by menuPass in the evaluated intrusion scenario.
Enterprise New Software: ... P8RAT
Remote access trojan that checks for processes associated with virtualized environments.
Remote access trojan observed as a payload in the APT10-attributed campaign.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.