SEAL RAT is a previously unreported malware family described in March 2026 as targeting Czech-speaking job seekers through a signed PE32+ dropper masquerading as an NDA-signing tool for Robert Walters s.r.o. The lure used a fabricated confidential job offer tied to EDEKA Czech Republic’s real 2026–2027 expansion plans, indicating targeted social engineering against Czech-speaking professionals in the job market. The Stage 1 dropper, observed as NDAvia_Nabidka_Linzer.exe, displayed a polished Czech-language GUI via an embedded Internet Explorer WebBrowser OLE control, harvested the victim’s full name through the fake NDA workflow, and captured keystrokes with GetAsyncKeyState while the window was active. It also supported a silent /s mode and forced IE11 rendering through FEATURE_BROWSER_EMULATION registry settings. The second stage extracted an encrypted blob from resources and used a proof-of-work anti-analysis delay before decrypting and launching the embedded RAT. The RAT communicated over HTTP POST to http://sealchecks.com/index.php using a custom binary protocol and the C2 returned the marker '<!--error-->ERROR # 1' to unrecognized requests. Reported capabilities include host reconnaissance; collection of hostname, username, language, CPU architecture, timezone, PID, MachineGUID, and domain membership; enumeration of 17 security products including CrowdStrike, SentinelOne, Carbon Black, Cylance, Sophos, Bitdefender, McAfee, Trend Micro, Norton, F-Secure, Dr.Web, Panda, Avast/AVG, Windows Defender, and Windows ATP; checking Windows Advanced Threat Protection onboarding state; remote shell execution via CreateProcessW/CreatePipe; arbitrary file download and execution; persistence through copy-and-rename installation; heartbeat communications; and typed data exfiltration. The malware family uses the name SEAL across version information, internal logging prefixes, and the C2 domain sealchecks.com. Reported sample and infrastructure indicators include Stage 1 SHA256 1096d2e220ecce73a4e7f0cdc673c2ff4f5b399693b2db5fc5dd098813633f19, Stage 2 SHA256 8c4a3a1de374dd996bc76f9f70f638690a428645e5e8181849f253268c4ca822, Stage 2 MD5 4d7457136a9621cb828c7e80608d6fa0, domain sealchecks.com, and IP 103.163.187.12. The dropper was signed with a short-lived Microsoft Trusted Signing AOC certificate issued to 'Robert Walters' and valid from 11 March 2026 to 14 March 2026. Attribution remains low confidence based on the available reporting.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
The dropper's .data section (60,416 bytes, entropy 7.91) contains the entire HTML UI, encrypted with a rolling-XOR scheme
MITRE ATT&CK Mapping Technique ID Detail Obfuscated Files or Information T1027.006 HTML UI encrypted in PE .data section
Masquerading: Match Legitimate Name T1036.005 Impersonates Robert Walters s.r.o.
MITRE ATT&CK Mapping Technique ID Detail Process Injection: Thread Execution Hijacking T1055.003 VirtualAlloc + VirtualProtect + CreateThread
MITRE ATT&CK Mapping Technique ID Detail Query Registry T1012 System and security product fingerprinting
System Information Discovery T1082 OS, CPU, hostname, MachineGUID, timezone
9 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A novel remote access trojan delivered by a signed dropper posing as a Czech-language NDA/job-offer tool. It uses a proof-of-work anti-analysis delay, decrypts an embedded payload, performs system and security-product reconnaissance, captures keystrokes in the lure stage, and supports remote shell execution, arbitrary file download/execute, persistence, heartbeat communications, and data exfiltration over HTTP.
A novel, previously unreported HTTP RAT delivered by a Czech-language recruitment-themed dropper. It performs system reconnaissance, fingerprints security products, provides remote shell access, downloads and executes arbitrary files, exfiltrates data, and installs persistence while communicating with its C2 over HTTP.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.