ElectroRAT is a custom cross-platform remote access trojan written in Go and used in a long-running campaign targeting cryptocurrency users. It was distributed through trojanized cryptocurrency-themed applications, including trading and poker software, that were promoted via dedicated websites, fake forum personas, social media accounts, and paid promotion in cryptocurrency communities. The malware was compiled for Windows, Linux, and macOS and embedded inside Electron-based applications so that a decoy graphical interface appeared while the RAT operated covertly in the background.
ElectroRAT provides broad remote-access and surveillance functionality. Reported capabilities include remote command execution, file upload and download, keylogging, screenshot capture, and general victim monitoring. On macOS, documented variants also deployed embedded auxiliary components for webcam capture, Chrome credential theft, and VNC-based remote control, indicating a highly intrusive post-compromise toolset aimed at both financial theft and persistent operator access.
The malware established persistence on multiple platforms. On Linux, it has been observed creating a desktop autostart entry. On macOS, it has been observed copying itself into the user profile and registering a launch agent to execute automatically at login. ElectroRAT also retrieved command-and-control information from Pastebin-hosted content before connecting to attacker infrastructure.
The campaign appears to have been active from at least January 2020 and was notable for combining custom malware development with a coordinated social-engineering and marketing operation. The operation targeted cryptocurrency holders and traders, and reporting linked parts of the surrounding infrastructure to activity associated with Amadey and KPOT, although ElectroRAT itself was a distinct custom malware family rather than a reuse of those strains. Its low detection rates during the campaign contributed to its effectiveness against victims across desktop operating systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
ElectroRAT is extremely intrusive. It has various capabilities such as keylogging, taking screenshots, uploading files from disk, downloading files and executing commands on the victim’s console.
As part of its behavioral flow, ElectroRAT contacts raw pastebin pages to retrieve the C&C IP address.
24 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Golang-based multi-platform remote access trojan embedded in trojanized cryptocurrency applications. It targets cryptocurrency users and supports keylogging, screenshots, file upload/download, and command execution to steal wallet-related and other sensitive information.
Mentioned only as an example of Linux malware using desktop autostart persistence.
A cross-platform RAT targeting cryptocurrency users, distributed via trojanized crypto apps. It steals personal information, credentials, and can execute commands, log keystrokes, take screenshots, and exfiltrate data.
ElectroRAT is a cross-platform remote access trojan (RAT) targeting cryptocurrency users. It is distributed via fake cryptocurrency applications and is capable of stealing personal information, keylogging, capturing screenshots, accessing the webcam, stealing Chrome passwords, and providing remote access via VNC. It achieves persistence on macOS via a launch agent and communicates with a C2 server to receive commands.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.