PoshRAT is a malware family observed in a complex 2025 cyber campaign targeting a government organization in Southeast Asia. It was one of multiple malware families deployed alongside HIUPAN, PUBLOAD, EggStremeFuel, EggStremeLoader, MASOL RAT, TrackBak Stealer, Hypnosis Loader, FluffyGh0st, and RawCookie in activity attributed to three China-aligned clusters: Mustang Panda (Stately Taurus), CL-STA-1048, and CL-STA-1049. The broader campaign was assessed by Palo Alto Networks Unit 42 as a well-resourced operation intended to establish long-term persistent access and exfiltrate sensitive data from government networks. The provided content confirms PoshRAT’s presence in this intrusion set, but does not provide specific technical details on its capabilities, infection vector, persistence mechanism, command-and-control behavior, or indicators of compromise.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Attackers deployed numerous malware families, including HIUPAN, PUBLOAD, EggStremeFuel, MASOL RAT, PoshRAT, TrackBak Stealer, Hypnosis Loader, and FluffyGh0st.
Attackers deployed numerous malware families, including HIUPAN, PUBLOAD, EggStremeFuel, MASOL RAT, PoshRAT, TrackBak Stealer, Hypnosis Loader, and FluffyGh0st.
Attackers deployed numerous malware families, including HIUPAN, PUBLOAD, EggStremeFuel, MASOL RAT, PoshRAT, TrackBak Stealer, Hypnosis Loader, and FluffyGh0st.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote access trojan used in the campaign to maintain stealthy access within the targeted environment.
Named malware family listed among those deployed in the campaigns; no further functional detail provided in the content.
PoshRat is a PowerShell-based remote access trojan (RAT) that provides attackers with persistent access and command execution capabilities on compromised systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.