Gorem RAT is a remote access trojan observed by Unit 42 in a cyberespionage campaign targeting a government organization in Southeast Asia between June and August 2025. It was used within the CL-STA-1048 activity cluster, which deployed an espionage toolkit including EggStremeFuel, Masol RAT, EggStreme Loader, Gorem RAT, and the TrackBak stealer. Unit 42 reported that EggStreme Loader, detected at C:\Windows\System32\XblAuthManagers.dll with SHA256 6caa78943939bd7518f5e7eaa44fa778d0db8b822e260d7fe281cf45513f82d9, was designed to launch Gorem RAT in memory. Gorem RAT used gRPC for command-and-control and also acted as a launcher for a user-mode keylogger module. In supporting reporting from JSAC2026, Palo Alto Networks again described CL-STA-1048 as using tools including RawCookie, EggStreme Loader, Gorem RAT, and Masol RAT, with possible links to Earth Estries assessed at low confidence. The broader CL-STA-1048 intrusion set was linked by Unit 42 to China-affiliated activity because Masol RAT and EggStreme had previously been publicly associated with campaigns such as Crimson Palace and Earth Estries.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
EggStreme Loader (which delivered the comprehensive Gorem RAT with keylogging)... The keylogger module performs the following activities: Capturing keystrokes... TrackBak is an infostealer that performs the following activities: Collecting key logs... CoolClient supports the following capabilities: Starting keylogging
EggStreme Loader (which delivered the comprehensive Gorem RAT with keylogging)... The keylogger module performs the following activities: Capturing keystrokes... TrackBak is an infostealer that performs the following activities: Collecting key logs... CoolClient supports the following capabilities: Starting keylogging
Variants of PUBLOAD use either HTTP or TCP for command-and-control (C2) communications. The sample we observed is a variant that uses TCP... Masol RAT... communicates with its C2 servers over HTTP POST... This malware uses Google Remote Procedure Call (gRPC) for C2 communication.
The backdoor supports the following capabilities: Uploading or downloading files... Masol RAT features backdoor commands for the following activities: ... Uploading or downloading a file... we observed a variant of Gorem RAT that implements a new feature to upload or download over Dropbox.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
RAT delivered by EggStreme Loader that uses gRPC for C2 and provides extensive backdoor functionality through 59 commands. It also launches a user-mode keylogger that captures keystrokes, window titles, clipboard contents, and network information, with a variant supporting Dropbox-based upload/download.
Remote access trojan used for interactive control of compromised hosts.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.