Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

FatalRAT

175
Global rank
187
Month rank
172 infographic chevron week
Week rank

FatalRAT is a malware that gives hackers remote access and control of the system and lets them steal sensitive information like login credentials and financial data. FatalRAT has been associated with cyber espionage campaigns, particularly targeting organizations in the Asia-Pacific (APAC) region.

RAT
Type
Unknown
Origin
1 August, 2021
First seen
18 July, 2026
Last seen

How to analyze FatalRAT with ANY.RUN

RAT
Type
Unknown
Origin
1 August, 2021
First seen
18 July, 2026
Last seen

IOCs

IP addresses
48.192.1.64
48.209.6.48
23.216.77.18
47.98.129.153
156.245.235.131
2.16.164.106
2.23.246.101
23.52.181.212
88.221.169.152
57.153.246.3
74.178.240.51
20.190.159.73
48.209.138.189
48.192.1.65
172.211.123.249
48.209.133.15
135.233.95.144
48.209.138.168
23.11.40.157
2.16.164.9
Hashes
09269b3283ae6299538da4edbe5a9bb0953f8898fffd1fdf214cd5d0b86a1719
2f1bbc9555787f4cc9561490c4ff9d7c18bc87d265e518f4444c97aabad18e15
a866507fc2cad0840f9f95b0aae828520b5413a23e48180a7db0455d49c0d417
c9f554d83c6c3e02d0baccc1c2124112390e57136072b8282ae24c04e4796694
cd05079b477e0c418932cbc005abcd11e08ee2a71befac8bc47c2b89327597ad
77259bdbac12510dea848e94759183c77e737b076efe206b914141db0732a8f0
28c8d02fb0f8755cbf6425d656c876082a066c5f7191f8ee50b931be46de4c5d
b4dbc05f77125b3b003dfe8c8485f38717dc1cc62a5aec541185e11ed5866550
6c3b9d4ba0b05a4d0a598001736b35ea91adeb876795350c2d54794909f84d90
449576aa7710c8143653fa74b2dcdc3ecec3a7a3bb3c2f725031239ae2da9117
75895ecb4742fe5ac46c4aad879513b3501a78a477bb3e4e28e58416377b1547
e42ad2c37574cf6a93510badf7616782c8fbfe933c0ba2594d2f4df0af83f4f4
6d7c4f3e5eee7ed1b3bc2f82af854983fe8ff99236e8ab66bfea45a2630e7feb
0232a30602b4f3fe9209da868a68cdeefb0c9aee17b6c611b33b028a35570aa2
ba81c857ab0fba93222157639f456762a783226c4da33a2b80195fde19b66e0c
917e98ffe2c2bbecbe50543b4a8117b1bf3de2170a6142ceb0b35e29c96d974d
bb9ce1e08b2dd78edf42d7e7b1ee70f5c8b665a4342ee36832001bfda201a4fd
ba4338c16ff7503cd7ef48bdb158b87039dccf7c5f35da95f9f5c9c2bbd65f48
78fe60eb41745e0a60ae68d2fe73b8b6cc6bef291bbae88e91e381b6b7c89893
57a04ba7d38875844eed96093062c50c8d0e1ba8655c6331f3ed9cca7fdbdefd
Domains
google.com
self.events.data.microsoft.com
settings-win.data.microsoft.com
crl.microsoft.com
www.microsoft.com
slscr.update.microsoft.com
login.live.com
fe3cr.delivery.mp.microsoft.com
ocsp.digicert.com
activation-v2.sls.microsoft.com
client.wns.windows.com
nexusrules.officeapps.live.com
drive.usercontent.google.com
www.bing.com
docs.google.com
freedns.afraid.org
URLs
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/micsecserca2011_2011-10-18.crl
https://activation-v2.sls.microsoft.com/slactivateproduct/slactivateproduct.asmx?configextension=retail
http://www.microsoft.com/pkiops/crl/microsoft%20time-stamp%20pca%202010(1).crl
http://www.microsoft.com/pkiops/crl/microsoft%20ecc%20update%20signing%20ca%202.3.crl
http://www.microsoft.com/pkiops/crl/microsoft%20ecc%20update%20signing%20ca%202.2.crl
http://www.microsoft.com/pkiops/crl/microsoft%20update%20signing%20ca%202.2.crl
http://www.microsoft.com/pkiops/crl/microsoft%20update%20signing%20ca%202.3.crl
http://crl.microsoft.com/pki/crl/products/microoceraut_2010-06-23.crl
https://login.live.com/rst2.srf
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceaz1vqyrvgl0erhqlcpm8gy%3d
https://login.live.com/ppsecure/deviceaddcredential.srf
https://settings-win.data.microsoft.com/settings/v3.0/wsd/waasassessment?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&ring=retail&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=bad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=10.0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=waasassessment&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&servicingbranch=cb&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&honorwufbdeferrals=0&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
https://settings-win.data.microsoft.com/settings/v3.0/onesettings/client?osversionfull=10.0.19045.4046.amd64fre.vb_release.191206-1406&localdeviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&attrdataver=186&osuilocale=en-us&osskuid=48&app=wosc&appver=&isflightingenabled=0&telemetrylevel=1&devicefamily=windows.desktop
https://settings-win.data.microsoft.com/settings/v3.0/flightsettings/fsservice?processorclockspeed=3094&isretailos=1&oemmanufacturername=dell&flightingpolicyvalue=3&enablepreviewbuilds=4294967295&osversionfull=10.0.19045.4046.amd64fre.vb_release.191206-1406&managepreviewbuilds=3&branchreadinesslevelsource=0&attrdataver=186&processorcores=6&branchreadinesslevelraw=16&totalphysicalram=6144&tpmversion=0&oemmodelnumber=dell&systemvolumetotalcapacity=260281&deviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&app=fss&appver=10.0&smartactivehoursstate=1&activehoursstart=20&securebootcapable=0&activehoursend=13&devicefamily=windows.desktop
https://settings-win.data.microsoft.com/settings/v3.0/wsd/muse?processorclockspeed=3094&flightids=&updateoffereddays=4294967295&branchreadinesslevel=cb&oemmanufacturername=dell&isclouddomainjoined=0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&sku=48&activationchannel=retail&attrdataver=186&ismdmenrolled=0&processorcores=6&processormodel=amd%20ryzen%205%203500%206-core%20processor&totalphysicalram=6144&primarydisktype=4294967295&flightingbranchname=&chassistypeid=1&oemmodelnumber=dell&systemvolumetotalcapacity=260281&sampleid=95271487&deviceclass=windows.desktop&app=muse&disabledualscan=0&appver=10.0&oemsubmodel=j5cr&locale=en-us&isalwaysonalwaysconnectedcapable=0&ms=0&defaultuserregion=244&updateserviceurl=http%3a%2f%2fneverupdatewindows10.com&osver=10.0.19045.4046.amd64fre.vb_release.191206-1406&os=windows&deviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&deferqualityupdateperiodindays=0&ring=retail&deferfeatureupdateperiodindays=30
http://www.microsoft.com/pkiops/crl/microsoft%20ecc%20product%20root%20certificate%20authority%202018.crl
http://www.microsoft.com/pkiops/crl/microsoft%20ecc%20update%20secure%20server%20ca%202.1.crl
https://slscr.update.microsoft.com/sls/%7b522d76a4-93e1-47f8-b8ce-07c937ad1a1e%7d/x64/10.0.19045.4046/0?ch=686&l=en-us&p=&pt=0x30&wua=10.0.19041.3996&mk=dell&md=dell
https://fe3cr.delivery.mp.microsoft.com/clientwebservice/ping
Last Seen at

Recent blog posts

post image
5 Critical Pain Points of Modern US SOCs and...
watchers 2720
comments 0
post image
IronChain Ransomware Threatens Businesses wit...
watchers 4259
comments 0
post image
Threat Coverage Digest: New Malware Reports a...
watchers 11807
comments 0

What is FatalRat malware?

A Remote Access Trojan detected in August 2021, FatalRAT became known for targeting an array of industries in the Asia-Pacific region. It has hit government agencies, manufacturing, construction, IT, telecom, healthcare, energy, logistics, and transportation companies, particularly in countries like Taiwan, Malaysia, Japan, South Korea.

It specializes in unauthorized information access: captures input by keyloggers and makes screenshots; finds, encrypts, corrupts, and deletes user data. It doesn’t always demand a ransom, is often used for espionage, sabotage, stable persistent access to a compromised network, and as a vehicle for further attacks.

It employs a number of attack vectors to infiltrate network, mostly phishing and social engineering tactics. FatalRAT is also known to abuse legitimate services like Chinese myqcloud CDN and Youdao Cloud Notes to host and deliver its payloads. The malware also leverages DLL side-loading techniques, where a legitimate executable is used to load a malicious DLL, initiating the infection chain without raising immediate suspicion.

Once inside the network, FatalRAT gathers extensive system information, including external IP addresses, usernames, and details about installed security products, which it exfiltrates to a command-and-control (C2) server over an encrypted channel. It manipulates system settings, for example, disables the CTRL+ALT+DELETE lock function or changing screen resolution.

FatalRAT is sophisticated in evading detection and maintaining access. It performs up to 17 checks to detect virtual machines or sandbox environments and halts execution to avoid analysis if it detects some.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

FatalRAT Malware’s Prominent Features

  • Broad Industry Targeting: Its operators are versatile in choosing victims across important industries and do not limit themselves by the Asia-Pacific region.
  • Data Theft and Disruption: Beyond encryption (unlike traditional ransomware), FatalRAT focuses on espionage and sabotage — stealing sensitive data, logging keystrokes, and potentially destroying systems via MBR corruption.
  • Sophisticated Infrastructure: Its use of legitimate cloud services and encrypted C2 channels makes attribution and blocking challenging.
  • Persistence and Adaptability: Its ability to maintain access and adapt via remote commands increases the likelihood of prolonged compromise.

FatalRAT Execution Process and Technical Details

In spite of FatalRAT’s anti-detection and sandbox evasion proficiency, there is quite a selection of FatalRAT analysis sessions in ANY.RUN’s Interactive Sandbox — including fresh samples added by the community just recently.

View sandbox analysis

The attack begins with phishing emails or messages distributed through platforms like WeChat and Telegram. These communications often masquerade as legitimate tax documents or invoices, containing ZIP archives packed with loaders protected by tools such as AsProtect or UPX. Once executed, these loaders retrieve dynamically updated command-and-control (C2) configurations from legitimate cloud services, initiating the infection.

The loader sends HTTP requests to specific URLs, which respond with encrypted JSON containing links to additional modules. To evade detection, malware often abuses legitimate software — such as GoogleUpdate.exe — allowing it to operate surreptitiously within the infected system. It may also modify the registry’s autorun value to add itself, ensuring it starts automatically upon system reboot.

FatalRAT is only deployed after extensive anti-analysis checks, including registry scans for virtual environment artifacts and verification of locale settings to match predefined criteria. Once active, FatalRAT logs keystrokes, exfiltrates sensitive data through encrypted C2 channels, and enables remote control of the victim’s machine. Its capabilities include stealing credentials, capturing screenshots, recording audio and video, and manipulating files and processes on the infected system. This robust feature set makes FatalRAT a potent tool for espionage and data theft across targeted industries.

FatalRAT analysis in ANY.RUN’s sandbox FatalRAT sample detonated inside ANY.RUN's Interactive Sandbox

Once inside a network, FatalRAT exhibits a wide range of capabilities designed to maximize damage and maintain control:

  • Besides anti-VM and anti-sandbox checks, it evades detection by obfuscation network traffic; strings and configurations are encrypted using custom routines.
  • FatalRAT scans the system for security apps, is able to terminate security-related processes (e.g., rundll32.exe) or disable antivirus features.
  • By leveraging trusted platforms like Youdao Cloud Notes and myqcloud, FatalRAT disguises its C2 communications as normal cloud traffic.
  • The phased deployment (loader → configurator → payload) complicates detection, as each stage can appear benign until the final RAT is activated.
  • FatalRAT achieves persistence by modifying the Windows Registry (e.g., creating entries like Software\Microsoft\Windows\CurrentVersion\Run\SVP7) or setting up new services to ensure it runs at system startup.
  • It activates a keylogger to capture user inputs and can manipulate system settings, such as disabling the CTRL+ALT+DELETE lock function or changing screen resolution.
  • The malware can search for, delete, or corrupt user data (e.g., targeting browser data from Chrome or Internet Explorer) and even overwrite the Master Boot Record (MBR) to render systems inoperable.
  • It downloads additional tools like AnyDesk or UltraViewer for remote access, executes shell commands, and can start or stop proxies.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

What are the examples of the best-known FatalRAT attacks?

FatalRAT is relatively new compared to legacy RATs like SubSeven or Poison Ivy, and its attacks are often part of broader, less publicized campaigns attributed to Chinese-speaking groups. FatalRAT’s operations prioritize stealth and long-term access over immediate, headline-grabbing disruption. As a result, specific "named" attacks are scarce.

  • Exploitation of Router Vulnerabilities (August 2021): FatalRAT was distributed by exploiting a critical path traversal vulnerability (CVE-2021-20090) in routers with Arcadyan firmware. This vulnerability allowed unauthenticated remote attackers to bypass authentication on millions of routers, facilitating the spread of FatalRAT and compromising numerous devices.
  • Cryptocurrency Phishing Campaign (April 2024): Phishing campaign specifically targeting cryptocurrency users, particularly those using the Exodus crypto wallet. Attackers created deceptive websites mimicking legitimate cryptocurrency applications to lure victims into downloading malicious installers. These installers deployed FatalRAT alongside additional malware components like clippers and keyloggers. The campaign employed DLL side-loading techniques to evade detection, allowing attackers to steal sensitive information and manipulate cryptocurrency transactions.
  • Operation SalmonSlalom (February 2025): A sophisticated cyber campaign targeted industrial organizations across the APAC region. Attackers employed a multi-stage payload delivery system, utilizing Chinese myqcloud and Youdao Cloud Notes for hosting and command-and-control operations. The campaign delivered FatalRAT through phishing emails disguised as tax documents or invoices, aiming to compromise various sectors, including manufacturing, construction, IT, telecommunications, healthcare, energy, and logistics.

Gathering threat intelligence on FatalRAT malware

Threat intelligence helps build proactive defense against threats even as intricate as FatalRAT. Leverage tools like ANY.RUN’s Threat Intelligence Lookup to gather indicators like C2 domains and file hashes and update firewalls and IDS/IPS. Track emerging patterns in APAC-focused campaigns to anticipate new variants.

Via TI Lookup, you can find fresh recently analyzed samples, be sure to get actual IOCs and to stay on top of new tactics and methods of FatalRAT’s beneficiaries.

threatName:"fatalrat"

FatalRAT samples found via TI Lookup FatalRAT new samples

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

FatalRAT stands out as a stealthy, multi-faceted threat that blends espionage, disruption, and persistence. Its reliance on legitimate services, advanced evasion tactics, and broad targeting make it a formidable adversary.

By combining robust endpoint monitoring, network analysis, and real-time threat intelligence, organizations can detect and neutralize FatalRAT before it inflicts irreparable damage. Staying vigilant in high-risk regions like APAC and adapting defenses to its evolving tactics are key to staying ahead of this RAT.

Gather IOCs to defend your network against FatalRat with 50 trial requests to TI Lookup

HAVE A LOOK AT

UpCrypter screenshot
UpCrypter
upcrypter
UpCrypter is a sophisticated malware loader that functions as a delivery mechanism for remote access tools. Distributed through global phishing campaigns targeting Windows systems, this actively maintained tool serves as the central framework for deploying various RATs including PureHVNC, DCRat, and Babylon RAT, enabling attackers to establish persistent remote control over compromised systems.
Read More
Octo screenshot
Octo
octo coper
Octo malware, also known as ExobotCompact or Coper, is a sophisticated Android banking trojan that has evolved from earlier malware family Exobot. It poses a significant threat to financial institutions, mobile users, and enterprise networks.
Read More
Latrodectus screenshot
Latrodectus
latrodectus
Latrodectus is a malicious loader that is used by threat actors to gain a foothold on compromised devices and deploy additional malware. It has been associated with the IcedID trojan and has been used by APT groups in targeted attacks. The malware can gather system information, launch executables, and detect sandbox environments. It uses encryption and obfuscation to evade detection and can establish persistence on the infected device.
Read More
Loader screenshot
Loader
loader downloader
A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.
Read More
WhiteSnake screenshot
WhiteSnake
whitesnake
WhiteSnake is a stealer with advanced remote access capabilities. The attackers using this malicious software can control infected computers and carry out different malicious activities, including stealing sensitive files and data, recording audio, and logging keystrokes. WhiteSnake is sold on underground forums and often spreads through phishing emails.
Read More
GuLoader screenshot
GuLoader
guloader
GuLoader is an advanced downloader written in shellcode. It’s used by criminals to distribute other malware, notably trojans, on a large scale. It’s infamous for using anti-detection and anti-analysis capabilities.
Read More