Ratty, also referred to as jRAT in some reporting, is a Java-based remote access trojan used to provide attackers with persistent remote control over compromised systems. It is an open-source RAT and has been observed both as a standalone payload and as a malware family delivered by other loaders and droppers. Reported functionality includes remote access, internal reconnaissance, collection of system information, file upload and download, execution of additional malware, process control, and keyboard input capture. Reporting also characterizes it as persistent and stealth-oriented in some intrusions.
Ratty has been distributed through multiple delivery chains. It has been observed as a payload delivered by RATDispenser, an evasive JavaScript-based malware distribution framework spread via malicious email attachments. It has also appeared in infection chains involving staged droppers and in campaigns using Java archive lures disguised as benign documents or shipping-related files. Separate reporting links RATty delivery to email campaigns and to exploitation of ICTBroadcast vulnerability CVE-2025-2611. These patterns indicate use in both socially engineered and opportunistic intrusion activity.
The malware has been associated with cybercriminal operations and post-compromise activity. As of July 2025, Ratty was reported as newly associated with Scattered Spider, where it was described as a Java-based RAT used for persistent and stealthy internal reconnaissance. This aligns with broader Scattered Spider tradecraft centered on credential abuse, social engineering, data theft, and extortion-oriented intrusions against commercial and critical infrastructure organizations.
Because Ratty is Java-based, it is primarily associated with environments capable of executing Java archive payloads, most notably Windows enterprise endpoints in observed campaigns. Its role in intrusion chains is consistent with post-exploitation access, reconnaissance, and operator-controlled follow-on actions rather than autonomous destructive behavior.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
13 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Java-based remote access trojan used for persistence and stealthy internal reconnaissance.
An open-source Java RAT observed as a payload delivered by RATDispenser.
Java-based remote access trojan delivered in JAR files, including samples appended to MSI installers to disguise the payload.
RATty is a remote access trojan (RAT) delivered via email campaigns, used by attackers to gain remote access and control over compromised systems. In this context, it was deployed through exploitation of a vulnerability in ICTBroadcast call center software.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.