Researchers reported that Cobian RAT, a freely advertised remote access trojan distributed on underground forums, contained a hidden backdoor planted by its original author. The malware was marketed as a basic njRAT-style tool with common surveillance and remote-control features, including keylogging, webcam access, screen capture, and arbitrary code execution on infected systems.
Analysis found that an encrypted library inside the Cobian RAT builder allowed the author to silently take over machines infected by downstream operators and even lock those operators out of their own campaigns. The covert component retrieved a command-and-control address from a preset Pastebin page, giving the author centralized control and effectively turning other criminals’ distribution activity into a crowdsourced botnet-building scheme.

Pull IOCs and campaign context straight into your stack.
2 events from the most recent confirmed update back to the earliest known activity.
Zscaler ThreatLabZ reported that it had been monitoring the Cobian RAT malware family starting in February 2017. This marks the earliest explicitly dated activity described in the references.
Researchers found that the Cobian RAT builder distributed on underground forums contained a hidden encrypted library that let the original author take control of systems infected by downstream operators. The backdoor retrieved the author's command-and-control address from a preset Pastebin page and could even lock second-level operators out of their own infections.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.