FormerFirstRAT is a custom Windows backdoor associated with the DragonOK intrusion set and observed in targeted operations against Japanese organizations, including manufacturing and high-technology entities. It appeared as a follow-on payload in phishing-led campaigns in which first-stage malware established an initial foothold and then enabled deployment of additional remote-access tooling.
The malware provides remote administration capabilities typical of an operator-controlled backdoor. It gathers host profiling data including user and system attributes, privilege context, operating system details, language, and a victim identifier derived from local system characteristics. It supports command execution with output return, file-system browsing, file download, file deletion, exfiltration of victim information, and configurable sleep timing for beacon control.
FormerFirstRAT communicates with command-and-control infrastructure over HTTP, including use of port 443 without TLS protection. Its traffic is encrypted with AES-128 using a key derived via MD5 from a hard-coded string. For persistence, it creates autorun entries in Windows Run locations under either the current-user or local-machine hive.
The malware has been linked to a broader DragonOK toolchain that also included Sysget or HelloBridge, PlugX, PoisonIvy, NFlog, and NewCT. Reporting on the related Aveo malware family identified notable similarities to FormerFirstRAT, including overlapping implementation patterns and comparable command-and-control behavior, suggesting a related development lineage or closely connected operational cluster focused on Japanese-speaking targets.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
DragonOK has previously targeted Japanese high-tech and manufacturing firms, but we’ve identified a new backdoor malware, named “FormerFirstRAT,” deployed by these attackers.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
To encrypt the provided data, the malware makes use of the RC4 algorithm, using a key of ‘hello’.
Sysget communicates with this server using the HTTP protocol... FormerFirstRAT communicates using unencrypted HTTP over port 443... All data is sent via HTTP POST requests.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
FormerFirstRAT is described as a closely related malware family sharing encryption routines, code reuse, and similar C2 functionality with Aveo, and it was also observed targeting Japanese users.
A custom remote administration tool/backdoor used in the DragonOK campaign. It persists via Run registry keys, communicates over HTTP POST on port 443, encrypts traffic with AES-128 using an MD5-derived key from 'tucwatkins', and supports command execution, file browsing, file download, file deletion, sleep-timer changes, and victim information exfiltration.
A custom remote administration tool/backdoor used in the DragonOK campaign. It persists via Run registry keys, communicates over unencrypted HTTP on port 443, encrypts C2 data with AES-128 using an MD5-derived key from 'tucwatkins', profiles the victim host, and supports command execution, file browsing, file download/deletion, sleep-timer changes, and data exfiltration.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.