Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

FatalRAT

163
Global rank
180 infographic chevron month
Month rank
173 infographic chevron week
Week rank
0
IOCs

FatalRAT is a malware that gives hackers remote access and control of the system and lets them steal sensitive information like login credentials and financial data. FatalRAT has been associated with cyber espionage campaigns, particularly targeting organizations in the Asia-Pacific (APAC) region.

RAT
Type
Unknown
Origin
1 August, 2021
First seen
18 July, 2026
Last seen

How to analyze FatalRAT with ANY.RUN

RAT
Type
Unknown
Origin
1 August, 2021
First seen
18 July, 2026
Last seen

IOCs

IP addresses
48.192.1.64
48.209.6.48
23.216.77.18
47.98.129.153
156.245.235.131
2.16.164.106
2.23.246.101
23.52.181.212
88.221.169.152
57.153.246.3
74.178.240.51
20.190.159.73
48.209.138.189
48.192.1.65
172.211.123.249
48.209.133.15
135.233.95.144
48.209.138.168
23.11.40.157
2.16.164.9
Hashes
09269b3283ae6299538da4edbe5a9bb0953f8898fffd1fdf214cd5d0b86a1719
2f1bbc9555787f4cc9561490c4ff9d7c18bc87d265e518f4444c97aabad18e15
a866507fc2cad0840f9f95b0aae828520b5413a23e48180a7db0455d49c0d417
c9f554d83c6c3e02d0baccc1c2124112390e57136072b8282ae24c04e4796694
cd05079b477e0c418932cbc005abcd11e08ee2a71befac8bc47c2b89327597ad
77259bdbac12510dea848e94759183c77e737b076efe206b914141db0732a8f0
28c8d02fb0f8755cbf6425d656c876082a066c5f7191f8ee50b931be46de4c5d
b4dbc05f77125b3b003dfe8c8485f38717dc1cc62a5aec541185e11ed5866550
6c3b9d4ba0b05a4d0a598001736b35ea91adeb876795350c2d54794909f84d90
449576aa7710c8143653fa74b2dcdc3ecec3a7a3bb3c2f725031239ae2da9117
75895ecb4742fe5ac46c4aad879513b3501a78a477bb3e4e28e58416377b1547
e42ad2c37574cf6a93510badf7616782c8fbfe933c0ba2594d2f4df0af83f4f4
6d7c4f3e5eee7ed1b3bc2f82af854983fe8ff99236e8ab66bfea45a2630e7feb
0232a30602b4f3fe9209da868a68cdeefb0c9aee17b6c611b33b028a35570aa2
ba81c857ab0fba93222157639f456762a783226c4da33a2b80195fde19b66e0c
917e98ffe2c2bbecbe50543b4a8117b1bf3de2170a6142ceb0b35e29c96d974d
bb9ce1e08b2dd78edf42d7e7b1ee70f5c8b665a4342ee36832001bfda201a4fd
ba4338c16ff7503cd7ef48bdb158b87039dccf7c5f35da95f9f5c9c2bbd65f48
78fe60eb41745e0a60ae68d2fe73b8b6cc6bef291bbae88e91e381b6b7c89893
57a04ba7d38875844eed96093062c50c8d0e1ba8655c6331f3ed9cca7fdbdefd
Domains
google.com
self.events.data.microsoft.com
settings-win.data.microsoft.com
crl.microsoft.com
www.microsoft.com
slscr.update.microsoft.com
login.live.com
fe3cr.delivery.mp.microsoft.com
ocsp.digicert.com
activation-v2.sls.microsoft.com
client.wns.windows.com
nexusrules.officeapps.live.com
drive.usercontent.google.com
www.bing.com
docs.google.com
freedns.afraid.org
a1.nbdsnb2.top
a1.yydsnb1.top
oneocsp.microsoft.com
URLs
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/micsecserca2011_2011-10-18.crl
https://activation-v2.sls.microsoft.com/slactivateproduct/slactivateproduct.asmx?configextension=retail
http://www.microsoft.com/pkiops/crl/microsoft%20time-stamp%20pca%202010(1).crl
http://www.microsoft.com/pkiops/crl/microsoft%20ecc%20update%20signing%20ca%202.3.crl
http://www.microsoft.com/pkiops/crl/microsoft%20ecc%20update%20signing%20ca%202.2.crl
http://www.microsoft.com/pkiops/crl/microsoft%20update%20signing%20ca%202.2.crl
http://www.microsoft.com/pkiops/crl/microsoft%20update%20signing%20ca%202.3.crl
http://crl.microsoft.com/pki/crl/products/microoceraut_2010-06-23.crl
https://login.live.com/rst2.srf
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceaz1vqyrvgl0erhqlcpm8gy%3d
https://login.live.com/ppsecure/deviceaddcredential.srf
https://settings-win.data.microsoft.com/settings/v3.0/wsd/waasassessment?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&ring=retail&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=bad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=10.0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=waasassessment&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&servicingbranch=cb&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&honorwufbdeferrals=0&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
https://settings-win.data.microsoft.com/settings/v3.0/onesettings/client?osversionfull=10.0.19045.4046.amd64fre.vb_release.191206-1406&localdeviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&attrdataver=186&osuilocale=en-us&osskuid=48&app=wosc&appver=&isflightingenabled=0&telemetrylevel=1&devicefamily=windows.desktop
https://settings-win.data.microsoft.com/settings/v3.0/flightsettings/fsservice?processorclockspeed=3094&isretailos=1&oemmanufacturername=dell&flightingpolicyvalue=3&enablepreviewbuilds=4294967295&osversionfull=10.0.19045.4046.amd64fre.vb_release.191206-1406&managepreviewbuilds=3&branchreadinesslevelsource=0&attrdataver=186&processorcores=6&branchreadinesslevelraw=16&totalphysicalram=6144&tpmversion=0&oemmodelnumber=dell&systemvolumetotalcapacity=260281&deviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&app=fss&appver=10.0&smartactivehoursstate=1&activehoursstart=20&securebootcapable=0&activehoursend=13&devicefamily=windows.desktop
https://settings-win.data.microsoft.com/settings/v3.0/wsd/muse?processorclockspeed=3094&flightids=&updateoffereddays=4294967295&branchreadinesslevel=cb&oemmanufacturername=dell&isclouddomainjoined=0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&sku=48&activationchannel=retail&attrdataver=186&ismdmenrolled=0&processorcores=6&processormodel=amd%20ryzen%205%203500%206-core%20processor&totalphysicalram=6144&primarydisktype=4294967295&flightingbranchname=&chassistypeid=1&oemmodelnumber=dell&systemvolumetotalcapacity=260281&sampleid=95271487&deviceclass=windows.desktop&app=muse&disabledualscan=0&appver=10.0&oemsubmodel=j5cr&locale=en-us&isalwaysonalwaysconnectedcapable=0&ms=0&defaultuserregion=244&updateserviceurl=http%3a%2f%2fneverupdatewindows10.com&osver=10.0.19045.4046.amd64fre.vb_release.191206-1406&os=windows&deviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&deferqualityupdateperiodindays=0&ring=retail&deferfeatureupdateperiodindays=30
http://www.microsoft.com/pkiops/crl/microsoft%20ecc%20product%20root%20certificate%20authority%202018.crl
http://www.microsoft.com/pkiops/crl/microsoft%20ecc%20update%20secure%20server%20ca%202.1.crl
https://slscr.update.microsoft.com/sls/%7b522d76a4-93e1-47f8-b8ce-07c937ad1a1e%7d/x64/10.0.19045.4046/0?ch=686&l=en-us&p=&pt=0x30&wua=10.0.19041.3996&mk=dell&md=dell
https://fe3cr.delivery.mp.microsoft.com/clientwebservice/ping
Last Seen at

Recent blog posts

post image
US Finance Under Phishing Pressure: What the...
watchers 3153
comments 0
post image
A Single Canadian Tax Lure Spread into a 46-C...
watchers 8509
comments 0
post image
North Korean IT Workers Scheme: Detection IOC...
watchers 11265
comments 0

What is FatalRat malware?

A Remote Access Trojan detected in August 2021, FatalRAT became known for targeting an array of industries in the Asia-Pacific region. It has hit government agencies, manufacturing, construction, IT, telecom, healthcare, energy, logistics, and transportation companies, particularly in countries like Taiwan, Malaysia, Japan, South Korea.

It specializes in unauthorized information access: captures input by keyloggers and makes screenshots; finds, encrypts, corrupts, and deletes user data. It doesn’t always demand a ransom, is often used for espionage, sabotage, stable persistent access to a compromised network, and as a vehicle for further attacks.

It employs a number of attack vectors to infiltrate network, mostly phishing and social engineering tactics. FatalRAT is also known to abuse legitimate services like Chinese myqcloud CDN and Youdao Cloud Notes to host and deliver its payloads. The malware also leverages DLL side-loading techniques, where a legitimate executable is used to load a malicious DLL, initiating the infection chain without raising immediate suspicion.

Once inside the network, FatalRAT gathers extensive system information, including external IP addresses, usernames, and details about installed security products, which it exfiltrates to a command-and-control (C2) server over an encrypted channel. It manipulates system settings, for example, disables the CTRL+ALT+DELETE lock function or changing screen resolution.

FatalRAT is sophisticated in evading detection and maintaining access. It performs up to 17 checks to detect virtual machines or sandbox environments and halts execution to avoid analysis if it detects some.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

FatalRAT Malware’s Prominent Features

  • Broad Industry Targeting: Its operators are versatile in choosing victims across important industries and do not limit themselves by the Asia-Pacific region.
  • Data Theft and Disruption: Beyond encryption (unlike traditional ransomware), FatalRAT focuses on espionage and sabotage — stealing sensitive data, logging keystrokes, and potentially destroying systems via MBR corruption.
  • Sophisticated Infrastructure: Its use of legitimate cloud services and encrypted C2 channels makes attribution and blocking challenging.
  • Persistence and Adaptability: Its ability to maintain access and adapt via remote commands increases the likelihood of prolonged compromise.

FatalRAT Execution Process and Technical Details

In spite of FatalRAT’s anti-detection and sandbox evasion proficiency, there is quite a selection of FatalRAT analysis sessions in ANY.RUN’s Interactive Sandbox — including fresh samples added by the community just recently.

View sandbox analysis

The attack begins with phishing emails or messages distributed through platforms like WeChat and Telegram. These communications often masquerade as legitimate tax documents or invoices, containing ZIP archives packed with loaders protected by tools such as AsProtect or UPX. Once executed, these loaders retrieve dynamically updated command-and-control (C2) configurations from legitimate cloud services, initiating the infection.

The loader sends HTTP requests to specific URLs, which respond with encrypted JSON containing links to additional modules. To evade detection, malware often abuses legitimate software — such as GoogleUpdate.exe — allowing it to operate surreptitiously within the infected system. It may also modify the registry’s autorun value to add itself, ensuring it starts automatically upon system reboot.

FatalRAT is only deployed after extensive anti-analysis checks, including registry scans for virtual environment artifacts and verification of locale settings to match predefined criteria. Once active, FatalRAT logs keystrokes, exfiltrates sensitive data through encrypted C2 channels, and enables remote control of the victim’s machine. Its capabilities include stealing credentials, capturing screenshots, recording audio and video, and manipulating files and processes on the infected system. This robust feature set makes FatalRAT a potent tool for espionage and data theft across targeted industries.

FatalRAT analysis in ANY.RUN’s sandbox FatalRAT sample detonated inside ANY.RUN's Interactive Sandbox

Once inside a network, FatalRAT exhibits a wide range of capabilities designed to maximize damage and maintain control:

  • Besides anti-VM and anti-sandbox checks, it evades detection by obfuscation network traffic; strings and configurations are encrypted using custom routines.
  • FatalRAT scans the system for security apps, is able to terminate security-related processes (e.g., rundll32.exe) or disable antivirus features.
  • By leveraging trusted platforms like Youdao Cloud Notes and myqcloud, FatalRAT disguises its C2 communications as normal cloud traffic.
  • The phased deployment (loader → configurator → payload) complicates detection, as each stage can appear benign until the final RAT is activated.
  • FatalRAT achieves persistence by modifying the Windows Registry (e.g., creating entries like Software\Microsoft\Windows\CurrentVersion\Run\SVP7) or setting up new services to ensure it runs at system startup.
  • It activates a keylogger to capture user inputs and can manipulate system settings, such as disabling the CTRL+ALT+DELETE lock function or changing screen resolution.
  • The malware can search for, delete, or corrupt user data (e.g., targeting browser data from Chrome or Internet Explorer) and even overwrite the Master Boot Record (MBR) to render systems inoperable.
  • It downloads additional tools like AnyDesk or UltraViewer for remote access, executes shell commands, and can start or stop proxies.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

What are the examples of the best-known FatalRAT attacks?

FatalRAT is relatively new compared to legacy RATs like SubSeven or Poison Ivy, and its attacks are often part of broader, less publicized campaigns attributed to Chinese-speaking groups. FatalRAT’s operations prioritize stealth and long-term access over immediate, headline-grabbing disruption. As a result, specific "named" attacks are scarce.

  • Exploitation of Router Vulnerabilities (August 2021): FatalRAT was distributed by exploiting a critical path traversal vulnerability (CVE-2021-20090) in routers with Arcadyan firmware. This vulnerability allowed unauthenticated remote attackers to bypass authentication on millions of routers, facilitating the spread of FatalRAT and compromising numerous devices.
  • Cryptocurrency Phishing Campaign (April 2024): Phishing campaign specifically targeting cryptocurrency users, particularly those using the Exodus crypto wallet. Attackers created deceptive websites mimicking legitimate cryptocurrency applications to lure victims into downloading malicious installers. These installers deployed FatalRAT alongside additional malware components like clippers and keyloggers. The campaign employed DLL side-loading techniques to evade detection, allowing attackers to steal sensitive information and manipulate cryptocurrency transactions.
  • Operation SalmonSlalom (February 2025): A sophisticated cyber campaign targeted industrial organizations across the APAC region. Attackers employed a multi-stage payload delivery system, utilizing Chinese myqcloud and Youdao Cloud Notes for hosting and command-and-control operations. The campaign delivered FatalRAT through phishing emails disguised as tax documents or invoices, aiming to compromise various sectors, including manufacturing, construction, IT, telecommunications, healthcare, energy, and logistics.

Gathering threat intelligence on FatalRAT malware

Threat intelligence helps build proactive defense against threats even as intricate as FatalRAT. Leverage tools like ANY.RUN’s Threat Intelligence Lookup to gather indicators like C2 domains and file hashes and update firewalls and IDS/IPS. Track emerging patterns in APAC-focused campaigns to anticipate new variants.

Via TI Lookup, you can find fresh recently analyzed samples, be sure to get actual IOCs and to stay on top of new tactics and methods of FatalRAT’s beneficiaries.

threatName:"fatalrat"

FatalRAT samples found via TI Lookup FatalRAT new samples

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

FatalRAT stands out as a stealthy, multi-faceted threat that blends espionage, disruption, and persistence. Its reliance on legitimate services, advanced evasion tactics, and broad targeting make it a formidable adversary.

By combining robust endpoint monitoring, network analysis, and real-time threat intelligence, organizations can detect and neutralize FatalRAT before it inflicts irreparable damage. Staying vigilant in high-risk regions like APAC and adapting defenses to its evolving tactics are key to staying ahead of this RAT.

Gather IOCs to defend your network against FatalRat with 50 trial requests to TI Lookup

HAVE A LOOK AT

Remcos screenshot
Remcos is a commercially distributed remote administration and surveillance tool that has been widely observed in unauthorized deployments, where threat actors use it to perform remote actions on compromised machines. It is actively maintained by its vendor, with new versions and feature updates released on a frequent, near-monthly basis.
Read More
Octo screenshot
Octo
octo coper
Octo malware, also known as ExobotCompact or Coper, is a sophisticated Android banking trojan that has evolved from earlier malware family Exobot. It poses a significant threat to financial institutions, mobile users, and enterprise networks.
Read More
Salty 2FA screenshot
Salty 2FA
salty2fa
Salty 2FA is a sophisticated Phishing-as-a-Service (PhaaS) framework tailored to hijack user sessions, steal credentials, and gain unauthorized access to corporate systems. Delivered primarily via targeted emails, this kit employs multi-stage evasion tactics, making it a stealthy tool for cybercriminals aiming at high-value enterprise accounts.
Read More
Phishing kit screenshot
Phishing kit
tycoon evilproxy sneaky2fa
Phishing kits are pre-packaged sets of malicious tools designed to make it easy for cybercriminals to launch phishing attacks. These kits replicate legitimate websites, steal credentials, and often include backend infrastructure for managing stolen data.
Read More
Phobos screenshot
Phobos
phobos ransomware
Phobos is a ransomware that locks or encrypts files to demand a ransom. It uses AES encryption with different extensions, which leaves no chance to recover the infected files.
Read More
NetSupport RAT screenshot
NetSupport RAT
netsupport
NetSupport RAT is a malicious adaptation of the legitimate NetSupport Manager, a remote access tool used for IT support, which cybercriminals exploit to gain unauthorized control over systems. It has gained significant traction due to its sophisticated evasion techniques, widespread distribution campaigns, and the challenge it poses to security professionals who must distinguish between legitimate and malicious uses of the underlying software.
Read More