MASOL RAT is a cross-platform remote access trojan and backdoor associated with China-aligned cyberespionage activity, particularly clusters overlapping with Earth Estries and related operations targeting Southeast Asian government and telecommunications environments. It has been observed since at least 2020 and has been deployed against both Windows and Linux systems, including Linux devices in Southeast Asian government networks. The malware is used to establish persistent remote access and support long-term espionage objectives.
Documented MASOL RAT functionality includes arbitrary command execution, file upload and download, backdoor access, and command-and-control communications over HTTP-based channels. Reporting also links it to keylogging and in-memory payload execution in some intrusion sets. In Windows intrusions, MASOL RAT has appeared alongside other espionage tooling such as EggStremeFuel, EggStreme Loader, Gorem RAT, and TrackBak, indicating use as part of a broader modular post-compromise toolkit focused on surveillance, credential and data collection, and sustained access.
MASOL RAT has been tied to campaigns against government entities and telecommunications-related targets in Southeast Asia, and has also been discussed in connection with exploitation of internet-facing enterprise infrastructure by Earth Estries, although some specific delivery-path attributions remain low confidence. High-confidence reporting supports its role as a backdoor used after compromise rather than a standalone initial-access mechanism. Its cross-platform design, remote administration features, and use in long-duration state-linked espionage operations make it a notable tool in the China-aligned intrusion ecosystem.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2022-3236 A code injection vulnerability in the User Portal and Webadmin of Sophos Firewall allows for remote code execution. | Furthermore, we discovered that Earth Estries uses another cross-platform backdoor, which we initially identified during our investigation of Southeast Asian government incidents in 2020. We named it MASOL RAT based on its PDB string.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Furthermore, we discovered that Earth Estries uses another cross-platform backdoor, which we initially identified during our investigation of Southeast Asian government incidents in 2020. We named it MASOL RAT based on its PDB string.
Attackers deployed numerous malware families, including HIUPAN, PUBLOAD, EggStremeFuel, MASOL RAT, PoshRAT, TrackBak Stealer, Hypnosis Loader, and FluffyGh0st.
Attackers deployed numerous malware families, including HIUPAN, PUBLOAD, EggStremeFuel, MASOL RAT, PoshRAT, TrackBak Stealer, Hypnosis Loader, and FluffyGh0st.
Attackers deployed numerous malware families, including HIUPAN, PUBLOAD, EggStremeFuel, MASOL RAT, PoshRAT, TrackBak Stealer, Hypnosis Loader, and FluffyGh0st.
Masol RAT and EggStreme Loader provided backdoor access, keylogging, and in-memory payload execution, while TrackBak stole keystrokes, clipboard data, and network info.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
Variants of PUBLOAD use either HTTP or TCP for command-and-control (C2) communications. The sample we observed is a variant that uses TCP... Masol RAT... communicates with its C2 servers over HTTP POST... This malware uses Google Remote Procedure Call (gRPC) for C2 communication.
EggStremeFuel, a lightweight backdoor that's equipped to download/upload files... EggStremeLoader... supports 59 backdoor commands... This includes a variant that facilitates file download/upload over Dropbox. MASOL RAT... with file download/upload... COOLCLIENT... supports file download/upload.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A cross-platform remote access trojan/backdoor observed on Linux devices targeting Southeast Asian government networks. The report says it may have been developed as early as 2019 and was later observed in Linux variants in the wild after 2021.
Remote access trojan used in the campaign to provide persistent access to compromised systems.
A remote access trojan that provides backdoor access, keylogging, and in-memory payload execution.
Remote access trojan with file download/upload and arbitrary command execution capabilities.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.