PythonRAT is a Python-based remote access tool observed in a cluster of malware campaigns associated with CastleLoader and related follow-on payloads. It has been linked to intrusion activity that also deployed NetSupport RAT and CastleStealer, indicating its use as part of broader multi-stage malware operations rather than as a standalone commodity infection chain. The malware is associated with campaigns that relied on staged loaders, shellcode execution, and scripted runtimes to deliver remote-access functionality onto victim systems.
Available reporting supports classifying PythonRAT as remote-access malware used in Windows-focused campaign activity. It is documented in related campaigns distributed through ClickFix-style lures, placing it within socially engineered delivery chains that trick users into initiating execution. The broader campaign ecosystem around it used obfuscated stagers, in-memory loading, and varied payload selection, suggesting PythonRAT was one of several interchangeable post-compromise tools used by the operators. High-confidence public details on PythonRAT’s internal feature set beyond its remote-access role are limited in the available material.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Python-based remote access tool observed in related CastleLoader campaigns and distributed via ClickFix-style lures.
A remote access trojan observed in campaigns related to CastleLoader activity.
A Python-based remote access tool previously observed in related campaigns and distributed via ClickFix-style lures.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.