Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Parallax RAT

174
Global rank
149 infographic chevron month
Month rank
152 infographic chevron week
Week rank
0
IOCs

Parallax RAT is a versatile malware capable of stealing credentials, recording keystrokes, capturing screenshots, and exfiltrating sensitive data. It hides under legitimate processes like Notepad, uses diverse communication channels, and establishes persistence to maintain control over infected machines.

RAT
Type
Unknown
Origin
1 December, 2019
First seen
5 August, 2026
Last seen

How to analyze Parallax RAT with ANY.RUN

RAT
Type
Unknown
Origin
1 December, 2019
First seen
5 August, 2026
Last seen

IOCs

IP addresses
20.190.159.73
172.217.208.91
142.251.14.138
48.192.1.64
4.150.223.99
2.16.164.130
2.23.246.9
184.31.95.119
72.5.43.93
23.11.40.157
48.209.6.48
150.171.110.177
142.251.151.119
48.209.133.15
57.153.246.3
52.123.243.76
74.178.240.61
135.233.95.135
162.125.72.15
162.125.72.18
Hashes
0e60b52689f3627486b9a77bb4f88bea0d8665a94f7f1ffc960a1fbc427626b7
40c2149635ede9666f001c9d9135b0b4bf649986459e1c4c52e2c65e79f29d7d
8cbbdc48821190ccc33949fb8f8d021399ddbd526f770a8e86afae1c19e8d3e5
ae5d71054ede722ca536030c3010fecb3f6ce424a0a7518978bdbf2d32003b19
0a056b3b33d7a1d07a12e730a39d3f201d59d096421e6d0ddef881c2371a25e3
b7f4b1c11dae16e35b78f10d73d359781b54c5b64718ea30aa33e16565ba5f42
cfe5e390be0f7d9672669e62d06baf6a8479f57c0906791039423ca4119a394c
eaea1c7eeb2af4fcb59c7db541df61057c4ccdb8a4d4f70af75776d70aa1850c
88301f0b7e96132a2699a8bce47d120855c7f0a37054540019e3204d6bcbaba3
138e49660d259061d8152137abd8829acdfb78b69179890beb489fe3ffe23e0c
c35020473aed1b4642cd726cad727b63fff2824ad68cedd7ffb73c7cbd890479
c3338f7c5cd465788643d4a5d5eb920a8411dbf2a1c9cdc8efa361d277e3ac49
7852fce59c67ddf1d6b8b997eaa1adfac004a9f3a91c37295de9223674011fba
90bf6baa6f968a285f88620fbf91e1f5aa3e66e2bad50fd16f37913280ad8228
b1e963d702392fb7224786e7d56d43973e9b9efd1b89c17814d7c558ffc0cdec
05eeba4d6ca7148dcd0a6317a45241a49a4c8d88d628b27d8b19889ef6e70771
8d21fe1bd251856bfaeaedd6a72ab78f153a047b6042e0fc614f57a32b56d340
f36e9baeb8e56b8d34d4833caf25cd28d2b4be214016dc068abfff3535c11635
a0956386dc64fd9f4883c8741f950cd60a56859616b159c9e4251c9eb0ac5534
3c88fd9805746be38b8d567b81dccee7c790ed17ca58902e69506b1e4c41fd3f
Domains
messaging.lifecycle.office.com
uc9cab4b35f275310dc83fa29715.dl.dropboxusercontent.com
safebrowsing.googleapis.com
clients2.google.com
settings-win.data.microsoft.com
messaging.engagement.office.com
watson.events.data.microsoft.com
www.google.com
fs.microsoft.com
self.events.data.microsoft.com
client.wns.windows.com
officeclient.microsoft.com
slscr.update.microsoft.com
go.microsoft.com
www.dropbox.com
accounts.google.com
www.microsoft.com
ocsp.digicert.com
translate.googleapis.com
optimizationguide-pa.googleapis.com
URLs
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceaz1vqyrvgl0erhqlcpm8gy%3d
https://go.microsoft.com/fwlink/?linkid=2257403&clcid=0x409
http://clients2.google.com/time/1/current?cup2key=8:50r8uwbxjsytvxc8wlvbyqxv3ehptzwedi1-m8ipqa0&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
https://safebrowsingohttpgateway.googleapis.com/v1/ohttp/hpkekeyconfig?key=aizasya2klwbx3mkfo30om9lufyqhpqloa_bnhe
https://clientservices.googleapis.com/chrome-variations/seed?osname=win&channel=stable&milestone=133
https://share.google/zdvwr9xbvujqo5qye
https://accounts.google.com/listaccounts?gpsia=1&source=chromiumbrowser&json=standard
https://www.google.com/share.google?q=zdvwr9xbvujqo5qye
https://cc-cool.de/cptdght
https://cc-cool.de/__slv
https://cc-cool.de/favicon.ico
https://cc-cool.de/cptdght?__t=eyjrijoiccisimlwijoimtu4lje3my4xnjiuiiwiysi6iknwdernahqilcjlehaioje3odu5ndq2nzy4mzn9.bvyp87efna-gxc2xcazkudo_246lbrot9-7p_j64t24
https://translate.googleapis.com/translate_a/l?client=chrome&hl=en&key=aizasya2klwbx3mkfo30om9lufyqhpqloa_bnhe
https://www.dropbox.com/scl/fi/yce5urrk29zvx8lkwbow6/digital_asset_monitoring_and_status_inspection_20260805_doc.zip?rlkey=gvtcf9t546rm9xi7xx4kzjsco&st=qe6a5ley&dl=1
https://uc7194cd96861eb0ab7182f32af8.dl.dropboxusercontent.com/cd/0/get/dfpgbdjxqdqpyyrb3yan7vko-rcqdst8mhfxltr88laesh3hbwgc-rkofens2abmeylnosxwrwgq1mnsu0rbupedfm79expmhzlx9qxdpidyd8bggdv1zprydlohntwsomc3gc9r0rfapi-xgslvya-d/file?dl=1
https://update.googleapis.com/service/update2/json?cup2key=14:-mkuihkizc0t51enutrg66witdflkwghp9o207qe_k0&cup2hreq=78da38a09e7fec925ead7b1565fe49e77021a80f5620714581acb6a22deb0810
https://sb-ssl.google.com/safebrowsing/clientreport/download?key=aizasya2klwbx3mkfo30om9lufyqhpqloa_bnhe
https://login.live.com/ppsecure/deviceaddcredential.srf
https://settings-win.data.microsoft.com/settings/v3.0/wsd/waasassessment?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&ring=retail&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=bad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=10.0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=waasassessment&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&servicingbranch=cb&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&honorwufbdeferrals=1&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
Last Seen at

Recent blog posts

post image
Intelligence-Driven SOC: Modernizing Threat M...
watchers 8245
comments 0
post image
Supply Chain Security: How ANY.RUN Helps US a...
watchers 3788
comments 0
post image
Smile, You're on Camera. Part 2: Hiring Lazar...
watchers 37063
comments 0

What is Parallax RAT malware?

Parallax RAT, a remote access Trojan (RAT) active since December 2019. It has gained notoriety for its evasion techniques, such as process hollowing, and extensive data exfiltration capabilities.

The malware has been widely used by various APTs around the world, including in attacks during the COVID-19 pandemic. ParallaxRAT has also been linked to the activity of the advanced persistent threat (APT) named TA2541 that has been targeting aviation and defense industry actors since 2017.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

Technical details of the Parallax RAT malicious software

Parallax RAT’s architecture enables attackers to engage in diverse malicious activities. The most common of them are:

  • Credential theft: Steals login credentials from various sources, including cached passwords, browser cookies, and Windows credential stores.
  • Keystroke logging: Captures every keystroke typed on the infected machine, including passwords, messages, and other sensitive data.
  • Screen capture: Periodically or on-demand captures screenshots of the infected machine's desktop, providing the attacker with visual information about the user's activity.
  • Uploading and downloading of files: Allows the attacker to upload and download files to/from the infected machine.
  • Information gathering: Beyond basic system information (name, OS), Parallax RAT uses various techniques for extensive data exfiltration. This includes scraping clipboard content.

Similar to other malware families, such as WarzoneRAT and DarkGate, Parallax RAT utilizes a sophisticated process-hollowing technique. It injects its malicious payload into a legitimate Windows process (e.g., pipanel.exe), leveraging the process's existing privileges to bypass security checks and remain undetected.

The malware usually establishes persistence by adding itself to the startup folder and creating scheduled tasks. Afterwards, Parallax RAT opens communication channels with the attacker's command-and-control (C2) server. One of the standout features of the malware is the use of Windows Notepad for communication with the victim. In many instances, attackers used this way of connecting with the victims to instruct them to visit the criminals’ Telegram channel.

Parallax RAT often employs a multi-stage delivery chain to evade detection. Initial stages might involve seemingly harmless files like weaponized Microsoft Word documents with embedded macros. Triggering these macros can download and execute the next stage payload, often a malicious DLL.

Execution process of Parallax RAT

To see how Parallax RAT infection takes place and collect its indicators of compromise, we can use ANY.RUN. Let’s submit a PrallaxRAT sample for analysis.

Parallax utilizes various techniques to infect targeted systems and establish persistence within them. In our analysis, it's evident that this malware generates a child process that promptly initiates malicious activities, including the theft of personal data, execution of injected code in a separate process, and the creation of files in the startup directory. Parallax employs injection techniques to conceal itself within legitimate processes, rendering detection challenging. In this instance, it is injected into the Explorer.exe system process. Furthermore, the Remote Access Trojan (RAT) also establishes connections to a Command and Control (C2) server to receive additional instructions.

ParallaxRAT process graph shown in ANY.RUN ParallaxRAT's process graph demonstrated in ANY.RUN

Distribution methods of the Parallax RAT malware

Attackers that engage in the distribution of Parallax RAT typically leverage phishing campaigns. They use emails impersonating trusted entities (e.g., banks) with malicious attachments or links. For instance, during the COVID-19 pandemic, many ParallaxRAT campaigns involved sending victims messages with attached archives that contained files responsible for further infection of the victim’s device.

Conclusion

Parallax RAT's reliance on email-based social engineering makes it crucial for organizations to ensure that there are appropriate mechanisms in place to prevent infection. One of the essential elements of a layered defense strategy is a malware analysis sandbox. It offers an isolated environment for safely executing any file or opening a link to determine if it poses a danger.

ANY.RUN is a malware analysis sandbox that provides an effortless cloud-based experience for analyzing files and links. The service swiftly identifies ParallaxRAT and dozens of other malware families and provides users with conclusive reports on the threat, featuring the malware’s TTPs and IOCs.

Try ANY.RUN for free – request a demo!

HAVE A LOOK AT

Havoc screenshot
Havoc
havoc
Havoc is an advanced post-exploitation framework used by hackers to take control of a system once they've breached it. With Havoc, attackers can run commands remotely, inject malicious processes, and access sensitive data. It's often used in targeted attacks, allowing cybercriminals to stay hidden in a network while stealing information or launching further attacks. Its flexibility and ability to bypass detection make it a serious threat, especially in environments that rely on traditional security tools.
Read More
Socelars screenshot
Socelars
socelars
Socelars is an information-stealing Trojan (often categorized as spyware/stealer) that focuses on collecting sensitive data from Windows systems, with standout reporting around Facebook Ads Manager and session cookie theft. Unlike “noisy” malware that immediately breaks something, Socelars quietly converts a single infected machine into access: logged-in sessions, business account data, and pathways to monetization.
Read More
Jigsaw screenshot
Jigsaw
jigsaw
The Jigsaw ransomware, initially detected in 2016, encrypts files on compromised systems and requires a ransom payment in Bitcoin. If the ransom is not paid, the malware starts deleting files, increasing the pressure on victims to comply. Its source code is publicly accessible, allowing various threat actors to customize and repurpose the malware for different objectives.
Read More
Rootkit screenshot
Rootkit
rootkit bootkit
A rootkit is a type of malicious software designed to provide unauthorized administrative-level access to a computer or network while concealing its presence. Rootkits are tools used by cybercriminals to hide their activities, including keyloggers, spyware, and other malware, often enabling long-term system exploitation.
Read More
zgRAT screenshot
zgRAT
zgrat
zgRAT is a malware known for its ability to infect systems and exfiltrate sensitive data to command-and-control (C2) servers. It is primarily distributed through loader malware, as well as phishing emails. zgRAT employs various advanced techniques, including process injection and code obfuscation, to evade detection and maintain persistence on infected systems. The malware can also spread via USB drives and uses popular messaging platforms like Telegram and Discord for data exfiltration.
Read More
DeerStealer screenshot
DeerStealer
deerstealer
DeerStealer is an information-stealing malware discovered in 2024 by ANY.RUN, primarily targeting sensitive data such as login credentials, browser history, and cryptocurrency wallet details. It is often distributed through phishing campaigns and fake Google ads that mimic legitimate platforms like Google Authenticator. Once installed, it exfiltrates the stolen data to a remote command and control (C2) server. DeerStealer’s ability to disguise itself as legitimate downloads makes it particularly dangerous for unsuspecting users.
Read More