Pangolin8RAT is a remote access trojan associated with the Chinese-linked threat actor Tianwu. It has been observed in espionage-oriented intrusions, including operations targeting transportation organizations such as a Taiwanese rail company. Reporting on the malware highlights its continued evolution and its use alongside a custom Cobalt Strike Beacon, indicating an actively maintained toolset within a broader post-compromise intrusion framework.
Pangolin8RAT is part of a cluster of malware families that implement command-and-control over the KCP protocol, a low-latency reliable transport commonly carried over UDP. Comparative analysis has grouped it with other China-linked malware families such as Crosswalk and KeyPlug based on shared use of KCP-related functionality. This places Pangolin8RAT within a pattern of tradecraft favored in some Chinese espionage operations for covert remote administration and resilient command-and-control.
As a RAT, Pangolin8RAT is used to provide persistent remote access and post-exploitation control on compromised systems. Its operational context indicates use in targeted intrusions rather than indiscriminate crimeware campaigns. The malware has been linked to campaigns against organizations of strategic interest, particularly in East Asia, and appears suited to long-term access, operator tasking, and follow-on deployment of additional tooling.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Naoki Takayama reported on the continued evolution of “Pangolin8RAT” and a custom Cobalt Strike Beacon associated with the Chinese-linked APT group “Tianwu.”
6 distinct techniques documented for this family, organized by ATT&CK tactic.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Plugin-extensible RAT/backdoor loaded in-memory via a loader; includes anti-forensics (log/data deletion after reboot) and stealthy C2 techniques (e.g., WebDAV abuse, cookie/Host-header manipulation).
Remote access trojan used by a China-associated intrusion set to compromise a Taiwanese rail-transportation company (described as plausible prepositioning).
Continuous Evolution of Tianwu’s Pangolin8RAT and Custom Cobalt Strike Beacon
Continuous Evolution of Tianwu’s Pangolin8RAT and Custom Cobalt Strike Beacon
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.