UBoatRAT is a remote access trojan used to provide interactive control over compromised Windows systems. Documented capabilities include enumerating running processes, launching a command shell, and communicating with operators over HTTP. It has also used trusted third-party web services, including GitHub and a public blogging platform, as command-and-control channels to blend malicious traffic with legitimate network activity and complicate detection and blocking. The observed functionality supports post-compromise reconnaissance and hands-on-keyboard operations by enabling operators to inspect host activity and execute commands remotely.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
Numerous entries state malware can create a remote shell or reverse shell, for example 4H RAT, BLACKCOFFEE, DarkComet, PlugX, QuasarRAT, and others. | The content repeatedly describes threat actors and malware using cmd.exe, the Windows command shell, to execute commands, launch payloads, run batch files, and automate actions on compromised hosts.
"Action RAT's commands, strings, and domains can be Base64 encoded within the payload." / "ADVSTORESHELL... strings... encrypted with an XOR-based algorithm; some strings are also encrypted with 3DES and reversed." / "APT29 has used encoded PowerShell commands." / "APT41 used VMProtected binaries..."
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications.
The adversaries had communicated to both Dropbox and Pastebin. APT28 has used Google Drive for C2. APT37 leverages social networking sites and cloud platforms (AOL, Twitter, Yandex, Mediafire, pCloud, Dropbox, and Box) for C2.
"Comnie uses blogs and third-party sites (GitHub, tumbler, and BlogSpot) to avoid DNS-based blocking"; "Revenge RAT used blogpost.com as its primary command and control server"; "Turla JavaScript backdoor has used Google Apps Script as its C2 server"
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote access trojan capable of listing running processes.
Remote access trojan that uses GitHub and public blog services for command-and-control.
Remote access trojan that uses GitHub and a public blog service for command and control.
RAT that uses HTTP for command-and-control (C2).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.