Shady RAT is described in the provided content as an indigenous Chinese remote access trojan (RAT) that emerged in the early wave of domestically developed malware following the release of Glacier, which is characterized as China’s first domestically created RAT. It is mentioned alongside Graybird, Net Thief, and YAI as part of this subsequent generation of Chinese RATs. The content places Shady RAT within the broader evolution of China’s early “red hacker” ecosystem, in which actors moved from website defacements and DDoS activity toward development and use of indigenous Trojans, RATs, and later more sophisticated offensive tooling. No specific technical capabilities, infection vectors, targeted industries, associated threat actor, or indicators of compromise are directly provided for Shady RAT in the supplied content beyond its classification as a RAT and its inclusion in this early Chinese malware lineage.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct technique documented for this family, organized by ATT&CK tactic.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as an indigenous Chinese RAT that followed Glacier; no additional details provided.
RAT referenced as part of early indigenous Chinese remote access tooling; also later referenced as an operation name in which HTRAN was used.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.