BIOPASS RAT is a Windows remote access trojan associated with China-aligned intrusion activity and most notably linked to the FishMonger cluster, also tracked as Earth Lusca and Aquatic Panda. It has appeared alongside other tooling such as ShadowPad, Cobalt Strike, FunnySwitch, Spyder, and SprySOCKS in espionage-oriented operations. Reported activity has connected BIOPASS RAT to campaigns targeting the online gambling sector in China, including watering-hole operations that compromised industry-relevant websites to reach victims.
The malware is used as a backdoor for remote operator access and post-compromise control. Reported tradecraft indicates overlap with modular intrusion frameworks and local inter-process communication patterns also seen in related tooling, including use of a localhost listener mechanism that can be checked by watering-hole scripts to determine whether a victim is already infected. Its operational use places it within broader campaigns involving stealth, staged delivery, and follow-on payload deployment.
Attribution reporting has linked BIOPASS RAT activity to Earth Lusca/FishMonger, a China-aligned espionage actor assessed to operate under the broader Winnti umbrella and believed by multiple researchers to be connected to the contractor I-SOON. Observed victimology and tooling associations indicate use primarily in cyberespionage and access operations against government and private-sector targets in Asia, as well as sector-specific targeting of gambling-related organizations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
This certificate was also used in the BIOPASS RAT campaign that we also reported on.
The group uses a variety of TTPs including but not limited to LoTL tactics, phishing, ransomware, cryptocurrency mining, supply chain attacks, China Chopper, Gh0st RaT, PlugX, HighNoon, Derusbi, BioPass RAT, RedXOR, and ShadowPad.
The group uses a variety of TTPs including but not limited to LoTL tactics, phishing, ransomware, cryptocurrency mining, supply chain attacks, China Chopper, Gh0st RaT, PlugX, HighNoon, Derusbi, BioPass RAT, RedXOR, and ShadowPad.
1 distinct technique documented for this family, organized by ATT&CK tactic.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A RAT campaign mentioned for certificate overlap and a similar localhost high-port HTTP listener technique used to detect prior infection during watering-hole attacks.
Named as part of FishMonger’s toolkit.
Named as part of FishMonger's wider espionage toolkit.
A remote access trojan listed as part of FishMonger’s toolset.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.