Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Parallax RAT

171
Global rank
131 infographic chevron month
Month rank
122 infographic chevron week
Week rank
0
IOCs

Parallax RAT is a versatile malware capable of stealing credentials, recording keystrokes, capturing screenshots, and exfiltrating sensitive data. It hides under legitimate processes like Notepad, uses diverse communication channels, and establishes persistence to maintain control over infected machines.

RAT
Type
Unknown
Origin
1 December, 2019
First seen
1 September, 2026
Last seen

How to analyze Parallax RAT with ANY.RUN

RAT
Type
Unknown
Origin
1 December, 2019
First seen
1 September, 2026
Last seen

IOCs

IP addresses
40.126.32.136
216.239.32.27
23.59.18.102
2.23.246.9
74.178.76.128
142.251.14.100
69.48.228.110
142.251.155.119
142.250.154.190
192.178.183.102
57.153.246.3
142.251.127.101
172.217.112.4
35.190.80.1
142.251.127.95
142.251.127.84
162.125.66.15
142.251.110.100
23.11.41.157
172.211.123.249
Hashes
b029393ea7b7cf644fb1c9f984f57c1980077562ee2e15d0ffd049c4c48098d3
c900ba9a2d8318263fd43782ee6fd5fb50bad78bf0eb2c972b5922c458af45ed
cb190e7d1b002a3050705580dd51eba895a19eb09620bdd48d63085d5d88031e
a08c1bc41de319392676c7389048d8b1c7424c4b74d2f6466bcf5732b8d86642
43daa4139d3ed90f4b4635bd4d32346eb8e8528d0d5332052fcda8f7860db729
329b20f56d6438f20aef784d9bd7b686dd16550dc84967bb5be3dc0a1c29ce18
16ce95d9bc2ba6a7e62fb16f19208ffe3f73f81cf2993f86dc5d6fa88443a43f
6f0f4073a60a2497ef460238a6888a4e4534c59d97f412558e293d1c1ce42a60
498e3205bf85da0a8f8b57e292d4bd12b31d691e04039c04bedcde75d1ea7459
a8a79d350c2a5e3bc36226633a8e0bed0dfab184e77f38fc8f0820ebacf8eafc
fb077c966296d02d50ccbf7f761d2a3311a206a784a7496f331c2b0d6ad205c8
eacd09517ce90d34ba562171d15ac40d302f0e691b439f91be1b6406e25f5913
f7b24f2eb3d5eb0550527490395d2f61c3d2fe74bb9cb345197dad81b58b5fed
3615498fbef408a96bf30e01c318dac2d5451b054998119080e7faac5995f590
ac354a4723aaa4f06bec385ddde4a4d0983ad51456f52b31a8068ec97d5b5ea7
ac11d818a7c8c23c971c321a367ddd1c0aa211898c078eb7f6a3ead32a1cf1f0
175c5a55f32076c23cac431cbe51ec4c58c9e369a4ed3a6d5db22b459d9a21b8
404375825191cf4c38e24422904cafb4ce8c919962f79131692dee100910aa26
ad357a66f00db56405499c9748b1a2018c06d57aa4f8e90417da54d4e904fc32
09f0dfc8ad03ce732876de80a9102c4e294f8e83b047a6a801a1b7e8956ca33c
Domains
clients2.google.com
slscr.update.microsoft.com
safebrowsingohttpgateway.googleapis.com
optimizationguide-pa.googleapis.com
www.dropbox.com
update.googleapis.com
359media.com
safebrowsing.googleapis.com
a.nel.cloudflare.com
client.wns.windows.com
settings-win.data.microsoft.com
login.live.com
fe3cr.delivery.mp.microsoft.com
crl.microsoft.com
edgedl.me.gvt1.com
clients1.google.com
go.microsoft.com
accounts.google.com
www.google.com
www.microsoft.com
URLs
https://safebrowsingohttpgateway.googleapis.com/v1/ohttp/hpkekeyconfig?key=aizasya2klwbx3mkfo30om9lufyqhpqloa_bnhe
https://share.google/36ic9du2ltmxh3jg3
https://accounts.google.com/listaccounts?gpsia=1&source=chromiumbrowser&json=standard
https://clientservices.googleapis.com/chrome-variations/seed?osname=win&channel=stable&milestone=133
http://clients2.google.com/time/1/current?cup2key=8:q0w8e71bcbp9ud2tsqnpdgoxvwuyowtdgl4od78ci9i&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
https://www.google.com/share.google?q=36ic9du2ltmxh3jg3
https://359media.com/3mdbdb9
https://go.microsoft.com/fwlink/?linkid=2257403&clcid=0x409
https://359media.com/favicon.ico
https://translate.googleapis.com/translate_a/l?client=chrome&hl=en&key=aizasya2klwbx3mkfo30om9lufyqhpqloa_bnhe
https://359media.com/__slv
https://a.nel.cloudflare.com/report/v4?s=sprrtgjricnn3%2bc9u00rbfkjenhjb%2fajlkmcz7sn2%2booxsm8b0rg6rsu23l%2bg8tdtemfmbxhdde50pr%2fk8wjfaxziu0qwbjz1gt8dbaujsptwa3yje%2fivg87yyrjnso%3d
https://359media.com/3mdbdb9?__t=eyjrijoiccisimlwijoimjeyljmwljm2ljiwiiwiysi6ijnnrgjeyjkilcjtijowlcjlehaioje3odgzmdcwmjq4nzd9.czisec-hnigt51lrgqgkri1xsxcoqqj5mtmusc7zute
https://login.live.com/rst2.srf
https://login.live.com/ppsecure/deviceaddcredential.srf
https://www.dropbox.com/scl/fi/3of8pihq4czpnetx7blv4/_web-_-_ref2026-jp09.zip?rlkey=rqwb67iw22ae95vc1hsn1196f&st=o92f2odq&dl=1
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceaz1vqyrvgl0erhqlcpm8gy%3d
https://uc39f2c7bf78d4c55fcd0f6d1e30.dl.dropboxusercontent.com/cd/0/get/dhuxxsg60yc6nbkbrn0de8i_4kqqrsz7vszpdbhvgijproflans0rwotajmu6ka8fnoyny6rir49qzozl6_8uqinucigmozvoueprhbuuuvz73j_3oivwf34gtb-m6h8bey7hmwqjx4rxoqnqlnmarq7/file?dl=1
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/micsecserca2011_2011-10-18.crl
Last Seen at

Recent blog posts

post image
Release Notes: Faster TI Investigations, Fres...
watchers 1374
comments 0
post image
Triage & Response Bottlenecks Eating into...
watchers 1930
comments 0
post image
Major Cyber Attacks in August 2026: US and EU...
watchers 6441
comments 0

What is Parallax RAT malware?

Parallax RAT, a remote access Trojan (RAT) active since December 2019. It has gained notoriety for its evasion techniques, such as process hollowing, and extensive data exfiltration capabilities.

The malware has been widely used by various APTs around the world, including in attacks during the COVID-19 pandemic. ParallaxRAT has also been linked to the activity of the advanced persistent threat (APT) named TA2541 that has been targeting aviation and defense industry actors since 2017.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

Technical details of the Parallax RAT malicious software

Parallax RAT’s architecture enables attackers to engage in diverse malicious activities. The most common of them are:

  • Credential theft: Steals login credentials from various sources, including cached passwords, browser cookies, and Windows credential stores.
  • Keystroke logging: Captures every keystroke typed on the infected machine, including passwords, messages, and other sensitive data.
  • Screen capture: Periodically or on-demand captures screenshots of the infected machine's desktop, providing the attacker with visual information about the user's activity.
  • Uploading and downloading of files: Allows the attacker to upload and download files to/from the infected machine.
  • Information gathering: Beyond basic system information (name, OS), Parallax RAT uses various techniques for extensive data exfiltration. This includes scraping clipboard content.

Similar to other malware families, such as WarzoneRAT and DarkGate, Parallax RAT utilizes a sophisticated process-hollowing technique. It injects its malicious payload into a legitimate Windows process (e.g., pipanel.exe), leveraging the process's existing privileges to bypass security checks and remain undetected.

The malware usually establishes persistence by adding itself to the startup folder and creating scheduled tasks. Afterwards, Parallax RAT opens communication channels with the attacker's command-and-control (C2) server. One of the standout features of the malware is the use of Windows Notepad for communication with the victim. In many instances, attackers used this way of connecting with the victims to instruct them to visit the criminals’ Telegram channel.

Parallax RAT often employs a multi-stage delivery chain to evade detection. Initial stages might involve seemingly harmless files like weaponized Microsoft Word documents with embedded macros. Triggering these macros can download and execute the next stage payload, often a malicious DLL.

Execution process of Parallax RAT

To see how Parallax RAT infection takes place and collect its indicators of compromise, we can use ANY.RUN. Let’s submit a PrallaxRAT sample for analysis.

Parallax utilizes various techniques to infect targeted systems and establish persistence within them. In our analysis, it's evident that this malware generates a child process that promptly initiates malicious activities, including the theft of personal data, execution of injected code in a separate process, and the creation of files in the startup directory. Parallax employs injection techniques to conceal itself within legitimate processes, rendering detection challenging. In this instance, it is injected into the Explorer.exe system process. Furthermore, the Remote Access Trojan (RAT) also establishes connections to a Command and Control (C2) server to receive additional instructions.

ParallaxRAT process graph shown in ANY.RUN ParallaxRAT's process graph demonstrated in ANY.RUN

Distribution methods of the Parallax RAT malware

Attackers that engage in the distribution of Parallax RAT typically leverage phishing campaigns. They use emails impersonating trusted entities (e.g., banks) with malicious attachments or links. For instance, during the COVID-19 pandemic, many ParallaxRAT campaigns involved sending victims messages with attached archives that contained files responsible for further infection of the victim’s device.

Conclusion

Parallax RAT's reliance on email-based social engineering makes it crucial for organizations to ensure that there are appropriate mechanisms in place to prevent infection. One of the essential elements of a layered defense strategy is a malware analysis sandbox. It offers an isolated environment for safely executing any file or opening a link to determine if it poses a danger.

ANY.RUN is a malware analysis sandbox that provides an effortless cloud-based experience for analyzing files and links. The service swiftly identifies ParallaxRAT and dozens of other malware families and provides users with conclusive reports on the threat, featuring the malware’s TTPs and IOCs.

Try ANY.RUN for free – request a demo!

HAVE A LOOK AT

JOMANGY screenshot
JOMANGY is a PHP webshell and backdoor family targeting vulnerable FreePBX servers. It is designed to establish long-term access to compromised VoIP infrastructure, enable toll fraud, and survive remediation attempts through multiple self-reinforcing persistence mechanisms. Unlike many traditional webshells, JOMANGY employs a highly resilient architecture that can automatically restore itself even after partial removal.
Read More
OnyxC2 screenshot
OnyxC2
onyxc2
OnyxC2 is a sophisticated Malware-as-a-Service platform sold on cybercrime forums that provides a turnkey solution for high-volume credential theft. The malware targets over 200 applications, scraping sensitive data from browsers, cryptocurrency wallets, and business-critical tools like FTP and email clients. It employs advanced evasion techniques, such as DLL sideloading and browser fingerprinting, to deliver encrypted payloads through legitimate signed binaries.
Read More
Cobalt Strike screenshot
Cobalt Strike
cobaltstrike
Cobalt Strike is a legitimate penetration software toolkit developed by Forta. But its cracked versions are widely adopted by bad actors, who use it as a C2 system of choice for targeted attacks.
Read More
Meduza Stealer screenshot
Meduza Stealer is an information-stealing malware primarily targeting Windows systems, designed to harvest sensitive data such as login credentials, browsing histories, cookies, cryptocurrency wallets, and password manager data. It has advanced anti-detection mechanisms, allowing it to evade many antivirus programs. The malware is distributed through various means, including phishing emails and malicious links. It’s marketed on underground forums and Telegram channels.
Read More
Greatness screenshot
Greatness is a Phishing-as-a-Service (PhaaS) platform that enables cybercriminals, even those with limited technical skills, to launch sophisticated phishing attacks primarily targeting Microsoft 365 (M365) credentials. It acts as a man-in-the-middle (MitM) proxy, facilitating credential theft and MFA bypass while providing affiliates with easy-to-use tools like attachment builders and Telegram notifications.
Read More
Phobos screenshot
Phobos
phobos ransomware
Phobos is a ransomware that locks or encrypts files to demand a ransom. It uses AES encryption with different extensions, which leaves no chance to recover the infected files.
Read More