Overlord RAT is a Golang-based, open-source remote access trojan targeting Windows systems. It has been deployed as a secondary payload in phishing-led compromises, including judicial- and tax-themed lures, as well as in exploitation of vulnerable WordPress sites. Observed delivery chains have used HTML smuggling with JavaScript, VBScript, and PowerShell, malicious virtual-disk images, and ClickFix social engineering that induces victims to run PowerShell commands. A variant called SpaceX1337 has credential-theft, cryptocurrency-theft, and hidden virtual network computing (HVNC) capabilities. Campaigns have used DLL sideloading, encrypted in-memory payload mapping, shellcode execution, and anti-analysis measures; HVNC functionality has also been injected into a legitimate Windows process. Persistence associated with SpaceX1337 deployment included COM hijacking. Overlord RAT has been observed in opportunistic post-exploitation activity following WordPress compromise, where attackers established unauthorized administrator access and deployed malicious plugins before attempting to download the RAT.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Цепочка CVE-2026-63030 (CVSS 9.8, Critical, CWE-436) + CVE-2026-60137 (CVSS 5.9, Medium, CWE-89) даёт pre-auth RCE... CVE-2026-63030: route confusion и обход авторизации batch endpoint. Предусловия: WordPress 6.9.0+. Batch endpoint /wp-json/batch/v1 доступен анонимно. | По данным The Hacker News, после эксплуатации наблюдалось создание более 100 backdoor-аккаунтов администраторов, развёртывание фейковых плагинов для code execution и попытки установки Overlord RAT - Golang-based remote access trojan.
CVE-2026-60137: SQL инъекция WordPress через author__not_in. Предусловия: WordPress 6.8.0+. Без CVE-2026-63030 требует аутентификацию... REST-контроллер экспонирует публичный параметр author_exclude и маппит его на WP_Query::author__not_in. | По данным The Hacker News, после эксплуатации наблюдалось создание более 100 backdoor-аккаунтов администраторов, развёртывание фейковых плагинов для code execution и попытки установки Overlord RAT - Golang-based remote access trojan.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
12 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote-access trojan delivered through a judicial-lure phishing campaign using HTML smuggling and a JavaScript/VBS/PowerShell execution chain; the report states that it injects HVNC functionality into RegSvcs.exe.
A remote access trojan used through a live C2 channel to exfiltrate sensitive files, browser sessions, internal messaging logs, and cryptocurrency wallet data, while maintaining persistent access.
An open-source remote access trojan delivered via a ClickFix-style attack and loaded directly into memory. The described variant, SpaceX1337, supports credential theft, cryptocurrency theft, and HVNC capabilities while using stealthy in-memory execution and persistence mechanisms to evade detection.
Golang-based remote access trojan attempted for installation after successful exploitation of the WordPress wp2shell chain.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.