tRat is a modular remote access Trojan written in Delphi and associated with TA505 activity in 2018. It was observed in phishing campaigns that used malicious Microsoft Office documents, including Word and Publisher files, with embedded macros that downloaded the malware after user interaction. Campaign lures used social-engineering themes such as shared documents, invoices, and travel-related branding, and at least one campaign appeared to target commercial banking institutions.
Once executed on Windows systems, tRat establishes persistence by copying itself to a user-accessible application-data location and creating a Startup shortcut so it launches automatically at logon. Its command-and-control traffic is encrypted and hex-encoded, and the malware performs an initial host-registration exchange that transmits basic victim-identifying information such as computer name, username, and a bot identifier. tRat is designed as a modular framework: operators can instruct it to retrieve additional encrypted DLL modules and execute them by export, allowing capabilities to be extended after initial compromise.
tRat fits TA505’s broader shift from large-scale malware delivery toward more targeted post-compromise access tooling. It has been described as a relatively little-documented backdoor/RAT used alongside other TA505 malware families and loaders. High-confidence reporting supports its use as a Windows-focused remote access platform for persistence, host profiling, and follow-on payload delivery.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
More recently, the group has been distributing a variety of remote access Trojans (RATs), among other information gathering, loading, and reconnaissance tools, including a previously undescribed malware we have dubbed tRat. tRat is a modular RAT written in Delphi...
13 distinct techniques documented for this family, organized by ATT&CK tactic.
TA505 semble avoir procédé à la distribution de ses charges malveillantes uniquement par campagnes de courriels d’hameçonnage... L’unique vecteur d’infection pour l’instant connu du mode opératoire TA505 demeure le courriel d’hameçonnage incluant une pièce jointe ou un lien malveillant.
On September 27, 2018, Proofpoint detected an email campaign in which malicious Microsoft Word documents used macros to download a previously undocumented RAT... On October 11, we observed another email campaign distributing tRAT... using both Microsoft Word and Microsoft Publisher files... In all cases, the attachments contained macros that, when enabled, downloaded tRat.
the attachments contained macros that, when enabled, downloaded tRat
malicious Microsoft Word documents used macros to download a previously undocumented RAT... Enabling the embedded macros installed tRat... In all cases, the attachments contained macros that, when enabled, downloaded tRat.
tRat achieves persistence by copying the binary to: C:\Users\<user>\AppData\Roaming\Adobe\Flash Player\Services\Frame Host\fhost.exe Next, tRat creates a LNK file in the Startup directory that executes the binary on startup: C:\Users\<user>\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\bfhost.lnk
tRat achieves persistence by copying the binary to: C:\Users\<user>\AppData\Roaming\Adobe\Flash Player\Services\Frame Host\fhost.exe Next, tRat creates a LNK file in the Startup directory that executes the binary on startup: C:\Users\<user>\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\bfhost.lnk
The documents abused the Norton brand, with the document names and embedded image suggesting that they were protected by a security product... This particular campaign... used a TripAdvisor lure... messages bearing malicious Microsoft Publisher documents purported to be from “Invoicing”... emails with malicious Microsoft Word attachments appeared to be from “Vanessa Brito”.
tRat uses TCP port 80 for command and control (C&C) communications; data are encrypted and transmitted hex-encoded.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A modular Delphi-based remote access trojan delivered via malicious macro-enabled Microsoft Word and Publisher attachments. It establishes persistence by copying itself into the user's AppData path and creating a Startup LNK, communicates with C2 over TCP port 80 using encrypted hex-encoded traffic, performs an initial AUTH_INF phone-home, and can retrieve and execute encrypted DLL modules from the C2.
Modular remote access trojan used by TA505; functionality depends on downloaded modules.
Modular backdoor/RAT used by TA505, with functionality extended through downloaded modules.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.