Parallax RAT, also known as ParallaxRAT, is a Windows remote access trojan that emerged in late 2019 and has been sold as a commodity malware offering. It has been distributed in spam and phishing campaigns, including malicious attachments such as Microsoft Word documents with macros and archive-based lures, and has also been delivered by other malware loaders including GuLoader. Coronavirus-themed and cryptocurrency-targeted campaigns have both been associated with its deployment.
Parallax RAT provides broad remote administration and surveillance functionality on compromised systems. Reported capabilities include remote command execution, file access and transfer, collection of system information, clipboard access, keystroke logging, screenshot capture, credential theft, and the ability to restart or shut down infected machines. It has also been observed notifying operators after infection and enabling interactive control of victims.
The malware uses multiple defense-evasion and execution techniques. Observed campaigns used a first-stage loader to decrypt the main RAT and inject it into legitimate Windows processes through process hollowing or related injection methods. Additional reporting describes shellcode-based staging, direct syscalls, remapping of ntdll to evade userland monitoring, and multi-process injection chains involving legitimate processes. Some samples stored encrypted configuration or payload data internally and used RC4 or XOR-based decryption during execution. Cleanup functionality has also been observed through a script that deletes the payload and removes traces.
Persistence mechanisms attributed to Parallax RAT include copying components into the Windows Startup folder, creating startup links, and creating scheduled tasks. It has been seen in campaigns targeting cryptocurrency organizations and in broader commodity-malware phishing operations. The malware is commonly discussed alongside other commodity RATs and stealers such as Agent Tesla, FormBook, NanoCore, NetWire, Remcos, and Warzone/Ave Maria, reflecting its role in financially motivated intrusion activity rather than a uniquely specialized platform.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
In this blog post, I’ll be diving into the technical details of the WinRAR vulnerability, identified as CVE-2025-8088. This vulnerability carries a high severity score of 8.4 and affects WinRAR on Windows operating systems due to a path traversal flaw. | The following threat actor groups are actively exploiting the vulnerability to deploy Remote Access Trojans (RATs) and infostealers. RAT (Parallax RAT) – Sample File name: DB FOLDER.rar
When the attachment is opened, an attempt to exploit the Microsoft Office Equation Editor vulnerability (CVE-2017-11882) will be launched and if the content is enabled, malicious macros will execute to install the RAT.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
As part of its persistence mechanism, scheduled tasks will be created to launch the malware at various intervals.
In some cases, scheduled tasks will also be created to launch the malware at various intervals.
The ParallaxRAT binary was extracted from memory and independently executed, wherein it drops a UN.vbs file and runs that using the wscript.exe tool.
When the attachment is opened, an attempt to exploit the Microsoft Office Equation Editor vulnerability (CVE-2017-11882) will be launched
As usual with these sort of attachments, users are prompted to Enable Editing and Enable Content, granting the attacker the ability to execute code on the endpoint to facilitate the delivery and execution of Emotet... Once the victim executed the file, Nanocore RAT was installed on the system
As part of its persistence mechanism, scheduled tasks will be created to launch the malware at various intervals.
In some cases, scheduled tasks will also be created to launch the malware at various intervals.
When executed, the RAT will either be copied to another location and executed or injected into another process. In a sample analyzed by BleepingComputer, Parallax was injected into the svchost.exe process and in another sample, Kremez saw it injected into cmd.exe.
This vulnerability carries a high severity score of 8.4 and affects WinRAR on Windows operating systems due to a path traversal flaw.
a loader downloading an image from the Imgur image sharing site that contains an embedded Parallax executable. This executable is then extracted from the image and launched on the computer.
When executed, the RAT will either be copied to another location and executed or injected into another process. In a sample analyzed by BleepingComputer, Parallax was injected into the svchost.exe process and in another sample, Kremez saw it injected into cmd.exe.
The attacker has the ability to read and record their victim's keystrokes, which are then encrypted and stored in the %appdata%\Roaming\Data\Keylog_<Data> directory.
After successfully infecting a victim's machine, the malware sends a notification to the attacker. They then interact with the victim by posing questions via Notepad and instructing them to connect to a Telegram channel.
37 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote access trojan listed as being deployed via exploitation of the WinRAR vulnerability.
A Windows remote access trojan delivered via malicious Word documents with embedded macros. The infection chain drops a DLL, injects shellcode into legitimate processes such as Notepad.exe, downloads a loader from Pastebin, retrieves an encrypted payload disguised as an image from Imgur, injects into cmd.exe, and establishes persistence via scheduled tasks. It uses direct syscalls and maps its own copy of ntdll to evade userland hooks and debugger breakpoints.
A commercially available remote access trojan used in phishing and spam campaigns that steals credentials, accesses files, logs keystrokes, gathers system and clipboard data, enables remote desktop/control of compromised machines, uses process hollowing for injection, persists via the Windows Startup folder, communicates with victims via Notepad/Telegram, and can remotely restart or shut down systems.
Named as one of the malware families delivered by Guloader.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.