Goat RAT is a Go-based remote access trojan associated with the North Korea-aligned Andariel threat group, which is widely linked to the Lazarus ecosystem. It has been observed in campaigns targeting organizations in South Korea, including universities, and fits a broader pattern of Andariel operations against defense, telecommunications, electronics, shipbuilding, manufacturing, and other strategic sectors. The malware has been tied to intrusion activity that abused vulnerable INNORIX Agent software for malware installation, and related Andariel tradecraft also includes likely spearphishing and other enterprise intrusion vectors.
Goat RAT is part of a larger Andariel toolset that includes multiple Go-developed implants and backdoors. It has been deployed under deceptive naming conventions previously seen in Andariel operations and appears intended to provide basic remote control over compromised Windows hosts. Documented functionality includes execution of system commands, collection of host network and process information through shell commands, basic file operations, and self-deletion. These behaviors are consistent with its use as an operator-controlled foothold for reconnaissance and post-compromise activity.
Reporting on recent campaigns places Goat RAT alongside other Andariel malware families such as TigerRAT, NukeSped variants, AndarLoader, Black RAT, and DurianBeacon, suggesting continuing evolution of the group’s tooling while preserving longstanding targeting and intrusion patterns. Available evidence supports classifying Goat RAT as a Windows-focused RAT used in espionage-oriented intrusions attributed to Andariel.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Over the last 15 years, the group has developed RATs, including the following... ▪ Goat RAT
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
2.1.1. Goat RAT 최근 국내 대학교들을 대상으로 한 공격에서 Innorix Agent가 악성코드를 설치했던 사례가 확인되었다.
Over the last 15 years, the group has developed RATs, including the following... ▪ Goat RAT
12 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Previously observed Go-based malware associated with Andariel, mentioned as background to the group's tooling evolution.
Andariel이 개발한 것으로 언급된 Go 기반 RAT 계열 악성코드.
A Go-based backdoor/RAT installed via abused Innorix Agent, using the filename 'iexplorer.exe'. The article notes file operations, self-deletion, and observed execution of system reconnaissance commands such as tasklist and ipconfig.
RAT used for remote access and lateral movement.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.