CollectionRAT is a Windows remote access trojan (RAT) used by the North Korean Lazarus Group. It was observed in campaigns exploiting CVE-2022-47966 in ManageEngine ServiceDesk to compromise organizations in Europe and the United States, alongside QuiteRAT. CollectionRAT provides standard RAT functionality including arbitrary command execution, file management, process creation for downloading and deploying additional payloads, reverse shell capability, host fingerprinting/system information collection, command-and-control tasking after registration, and self-removal on operator instruction. The malware is described as a packed Microsoft Foundation Class (MFC)-based Windows binary that decrypts and executes its core code in memory. Reporting links CollectionRAT to Lazarus infrastructure reuse and notes the same infrastructure also hosted QuiteRAT, DeimosC2, and a trojanized PuTTY Plink utility used for reverse tunneling. CollectionRAT is also assessed to be related to Jupiter/EarlyRAT based on a shared code-signing certificate artifact from 2021 with subject "OSPREY VIDEO INC." and the same serial number and thumbprint. The campaign context indicates Lazarus was increasingly using open-source tooling earlier in the intrusion chain, including an unmodified Linux ELF DeimosC2 agent. High-confidence indicators mentioned in the content include the shared certificate subject "OSPREY VIDEO INC." and campaign linkage to infrastructure reused for CollectionRAT command and control.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
CollectionRAT is a remote access trojan used by the Lazarus Group for data collection and persistent access in targeted attacks, often alongside other malware such as QuiteRAT.
Remote access trojan used by Lazarus Group; collects host/system information for fingerprinting, communicates with C2 over HTTP, executes arbitrary commands (including reverse shell), manages files, spawns processes to deploy additional payloads, and can self-remove. Implemented as a packed Windows MFC-based wrapper/decrypter that decrypts and executes the core code at runtime.
CollectionRAT is a remote access trojan attributed to the Lazarus Group, used for espionage and data collection. It is part of the group's evolving toolkit for persistent access and intelligence gathering.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.