Threat actors have used Parallax RAT, a low-cost remote access Trojan sold on criminal forums, in phishing and spam campaigns that compromise Windows systems and increasingly target cryptocurrency organizations. Delivery has relied on malicious Microsoft Word attachments, embedded macros, and exploits such as CVE-2017-11882, giving attackers full remote access for credential theft, file theft, clipboard monitoring, keylogging, command execution, and broader system control. Researchers reported that the malware has been active since late 2019 and has remained a common payload because of its low price and ease of deployment.
Technical analyses show Parallax RAT using multi-stage loaders, process hollowing, and persistence mechanisms including the Windows Startup folder and scheduled tasks. Recent samples decrypted payloads with RC4, injected into legitimate processes including pipanel.exe, Notepad.exe, mstsc.exe, and cmd.exe, and fetched additional components from services such as Pastebin and Imgur, while some command-and-control infrastructure used DuckDNS. Investigators also observed attacker interaction through Windows Notepad, victim instructions pointing to a Telegram channel, and cleanup scripts designed to delete payloads and remove traces after execution.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
Morphisec said Parallax RAT had been linked to several coronavirus-themed malware campaigns, expanding the known lure themes used to deliver the malware.
By early 2020, Parallax RAT was being widely distributed through malicious spam campaigns, giving attackers full control over infected Windows systems and enabling credential theft, file theft, and remote command execution.
Morphisec Labs reported observing Parallax RAT phishing documents targeting Windows machines since January 2020. The campaign used malicious Word documents with embedded macros to begin a multi-stage infection chain.
Parallax RAT began being distributed through spam campaigns and phishing emails with malicious attachments in December 2019. Delivery methods included malicious documents exploiting CVE-2017-11882 and macro-enabled files.
MalwareHunterTeam had been tracking Parallax RAT samples through VirusTotal and other malware submission services since December 2019, indicating the malware was already circulating in the wild.
Parallax RAT was offered for sale by the "Parallax Team" on hacker forums beginning in early December 2019, with low-cost subscription pricing that likely helped drive adoption.
Uptycs observed active Parallax RAT samples targeting cryptocurrency organizations. The campaign used phishing emails and collected private email addresses of cryptocurrency companies from dnsdumpster.com.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
blog.morphisec.com
Open sourceuptycs.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.