MostereRAT is a high-severity Windows remote-access trojan distributed through business-themed phishing campaigns targeting Japanese users. Victims are induced to follow malicious links, download a file, and open an embedded archive that executes the malware. MostereRAT uses Easy Programming Language (EPL), impeding analysis, and applies defense-evasion measures including interference with security products and Windows security features. Its command-and-control communications are protected with mutual TLS. The malware deploys legitimate remote-administration tools including AnyDesk and TightVNC, creates a concealed administrative user account for persistence, enables remote control of infected systems, collects data, and can install further payloads. It reportedly evolved from a banking trojan first observed in 2020.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Windows RAT mentioned only as a comparison for a document-decoy delivery technique.
Phishing-delivered malware that evolved from banking malware into a RAT; uses evasion, data theft, and plugin-based extensibility (per excerpt).
Remote access trojan distributed via phishing campaigns, enabling unauthorized access to infected systems.
MostereRAT is a Windows-targeting remote access trojan delivered through phishing emails. It uses EPL to hinder analysis, disables or interferes with security tools, uses mutual TLS for C2 communications, deploys remote access tools such as AnyDesk and TightVNC, and creates a hidden administrative user account for persistence and continued remote control.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.