Webinar
February 26
Better SOC with Interactive Sandbox
Practical Use Cases
Overlord RAT is a cross-platform remote access framework with Go-based agents and a TypeScript/Node/Bun server. It supports encrypted WebSocket C2, remote control, persistence, and multiple operating systems, including Windows, Linux, and macOS.
|
RAT
Type
:
|
Unknown
Origin
:
|
|
1 June, 2026
First seen
:
|
2 October, 2026
Last seen
:
|
|
Type
:
|
Unknown
Origin
:
|
|
1 June, 2026
First seen
:
|
2 October, 2026
Last seen
:
|
Overlord RAT detonated inside ANY.RUN’s Interactive Sandbox
Overlord RAT is a publicly available cross-platform remote access trojan (RAT) framework designed to provide remote access to compromised systems.
The framework uses Go-based agents, while its server-side components are implemented using TypeScript with Node.js/Bun. Operators can manage connected agents through a web-based interface or an Electron client.
Communication between agents and the C2 server takes place over encrypted WebSocket connections (WSS), providing a channel for exchanging commands and information.
The framework supports Windows, Linux, and macOS, making it applicable across multiple operating system environments. Its continued development also means that capabilities and implementation details may change between versions.
An Overlord RAT infection can create several risks for organizations, including:
Overlord RAT supports Windows, Linux, and macOS, potentially exposing organizations that operate mixed-OS environments.
The framework is not described as being restricted to a specific industry or sector. Its general-purpose remote-access capabilities can potentially be applied to a broad range of environments.
The impact of an infection can depend on the privileges available to the compromised agent, the system on which it is running, the configuration of the RAT, and the actions performed by the operator.
Observing an Overlord RAT sample inside ANY.RUN’s Interactive Sandbox shows that Overlord RAT uses a client-server architecture in which lightweight agents communicate with a central server operated through a web-based or Electron interface.
The agents are written in Go, while the server component uses TypeScript and Node.js/Bun. Communication between agents and the server takes place over encrypted WebSockets (WSS).
The observed Windows sample additionally uses several techniques intended to maintain access and make the malware appear less suspicious.
The general execution flow can be summarized as:
Agent execution → Persistence → Process masquerading → Encrypted C2 communication → Remote control
Overlord RAT detected in ANY.RUN’s Interactive Sandbox
Overlord RAT operates through an agent deployed to the target system.
The framework supports multiple operating systems, including Windows, Linux, and macOS. The Go-based agent is responsible for establishing communication with the server and carrying out actions received through the C2 channel.
On Windows, the analyzed sample is named: svchost-windows-amd64-a8d100a3.exe
The filename resembles the naming convention used by legitimate Windows system processes, helping the executable blend into the host environment.
The analyzed Windows sample establishes persistence using more than one mechanism.
First, the malware copies itself to: AppData\Roaming\Microsoft\DeviceSync\svchost.exe
It also places a copy in the Startup folder, allowing the malicious executable to be launched when the user logs into Windows.
Overlord RAT copies itself as svchost.exe to DeviceSync and Startup folder
In addition, the sample modifies a Windows Registry autorun key to establish another startup mechanism.
Registry autorun key modification for persistence
This combination provides redundant persistence, meaning that the malware has multiple ways to regain execution if one mechanism is removed.
The sample creates a mutex using a name associated with a legitimate Windows component: Global\BFE_Notify_Event_{...}
Overlord RAT masquerades as legitimate Windows BFE component mutex
The use of a name associated with the Windows Base Filtering Engine (BFE) can make the mutex appear less suspicious during analysis and may help the malware avoid standing out among legitimate system objects.
A mutex can also help malware coordinate execution and prevent multiple instances of the same component from running simultaneously.
After establishing itself on the system, the agent communicates with the Overlord server using encrypted WebSocket connections (WSS).
This provides a persistent communication channel through which the agent and server can exchange information and commands.
The framework's server component is implemented using TypeScript and Node.js/Bun, while operators can interact with connected agents through a web panel or Electron client.
The analyzed sample communicates with its C2 through an ngrok tunnel.
C2 via ngrok tunnel
Ngrok provides a tunnel between the infected system and the remote service, which can obscure the attacker's underlying infrastructure from the victim's network.
For defenders, this means that the visible destination may belong to the tunneling service rather than directly revealing the infrastructure operated by the attacker.
Once the agent establishes its C2 connection, the framework provides the operator with a mechanism for remotely managing the compromised host.
Commands can be issued through the framework's control interface and transmitted to connected agents through the C2 channel.
This remote-access capability is the central function of Overlord RAT and distinguishes it from malware designed solely for information collection or payload delivery.
Unlike Windows-only RATs, Overlord is designed as a cross-platform framework. Its agents support Windows, Linux, and macOS.
This architecture allows the same broader framework to be deployed across different operating system environments, although specific functionality may depend on the agent and platform.
The analyzed Windows sample demonstrates several notable behaviors:
Together, these capabilities allow Overlord RAT to establish a persistent presence, communicate with remote infrastructure, and provide operators with remote access to compromised systems.
Because Overlord is a developing RAT/framework, samples may differ in configuration, filenames, infrastructure, and implementation. Defenders should therefore combine static indicators with behavioral and network analysis.
ANY.RUN’s Threat Intelligence can help analysts investigate suspicious Overlord activity by connecting samples with associated infrastructure and observable behaviors.
Threat Intelligence Lookup can be used to pivot from a suspicious sample or indicator toward:
Searching for Overlord RAT in ANY.RUN’s Threat Intelligence Lookup
Defenders investigating potential Overlord RAT activity can monitor for:
These behaviors can provide useful detection opportunities even when filenames, hashes, or C2 destinations change.
If Overlord RAT is identified on an endpoint, organizations should investigate both the malware and the mechanisms used to maintain remote access.
Recommended actions include:
Because Overlord RAT provides remote access, defenders should also investigate what actions may have been performed while the agent was active.
Overlord RAT is a cross-platform remote access framework built around Go-based agents and a TypeScript/Node/Bun server architecture. Its agents communicate with the C2 infrastructure through encrypted WebSocket connections and can be managed through web or Electron-based interfaces.
The analyzed Windows sample demonstrates several behaviors relevant to defenders, including multiple persistence mechanisms, Windows process masquerading, mutex masquerading, encrypted C2 communication, and ngrok-based tunneling.
Monitoring for suspicious Startup and Registry modifications, unusual AppData executables, masquerading filenames, unexpected WSS connections, and ngrok-related traffic can help organizations identify potential Overlord RAT activity.
Overlord RAT is a publicly available cross-platform remote access trojan (RAT) framework designed to provide remote access to compromised systems. Its agents are written in Go, while the server component uses TypeScript with Node.js/Bun.
Overlord RAT supports Windows, Linux, and macOS, allowing the framework to operate across different operating system environments.
Overlord RAT supports encrypted WebSocket communication using WSS, allowing agents to exchange commands and information with the C2 server.
Yes. Overlord RAT can use persistence mechanisms to help maintain access to compromised systems after the initial execution. The specific mechanisms may vary depending on the platform and implementation.
Overlord RAT can employ masquerading techniques, such as using filenames or system object names that resemble legitimate components, to make malicious activity less conspicuous.
Overlord RAT can create mutexes as part of its execution. Depending on the implementation, mutex names may also be designed to resemble legitimate system components.
Overlord RAT can use tunneling services such as ngrok as part of its C2 infrastructure. Such services can provide an intermediary between the agent and remote infrastructure.
Interactive sandboxing allows analysts to examine Overlord RAT's execution, persistence, process activity, and network communications.
Threat intelligence can then help connect observed indicators with related samples, infrastructure, and other activity.