Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Parallax RAT

164
Global rank
120 infographic chevron month
Month rank
94 infographic chevron week
Week rank

Parallax RAT is a versatile malware capable of stealing credentials, recording keystrokes, capturing screenshots, and exfiltrating sensitive data. It hides under legitimate processes like Notepad, uses diverse communication channels, and establishes persistence to maintain control over infected machines.

RAT
Type
Unknown
Origin
1 December, 2019
First seen
18 September, 2026
Last seen

How to analyze Parallax RAT with ANY.RUN

RAT
Type
Unknown
Origin
1 December, 2019
First seen
18 September, 2026
Last seen

IOCs

IP addresses
74.179.77.164
150.171.28.11
95.100.102.101
150.171.22.17
35.190.80.1
48.209.138.168
172.211.123.249
95.100.102.9
40.126.32.138
172.67.175.142
150.171.109.100
20.165.94.63
48.192.1.64
23.216.77.36
150.171.109.101
172.211.123.248
150.171.27.11
48.209.138.189
2.16.241.201
162.125.66.18
Hashes
b029393ea7b7cf644fb1c9f984f57c1980077562ee2e15d0ffd049c4c48098d3
b9fa2d52a4ffabb438b56184131b893b04655b01f336066415d4fe839efe64e7
3a5078b626e41d20117d260d8b825b039884cfe062c6d462432216d9b07d82b5
75da533888189d13fc340d40637b9fc07a3f732e3fcf33ec300f4c7268790a62
907f2709d1d3c8fa26294938f4080bc477e62281c4c50a082c22db0195cda663
22ca9415e294d9c3ec3384b9d08cdaf5164af73b4e4c251559e09e529c843ea6
474d668707f1cb929fef1e3798b71b632e50675bd1a9dceaab90c9587f72f680
3d0361a85adfcd35d0de74135723a75b646965e775188f7dcdd35e3e42db788e
6028bd681dbf11a0a58dde8a0cd884115c04caa59d080ba51bde1b086ce0079d
9c70f766d3b84fc2bb298efa37cc9191f28bec336329cc11468cfadbc3b137f4
eacd09517ce90d34ba562171d15ac40d302f0e691b439f91be1b6406e25f5913
3dbd2c90050b652d63656481c3e5871c52261575292db77d4ea63419f187a55b
b3ece279943b28c8d855ec86ac1ce53bdfb6a709240d653508764493a75f7518
4ecedb9c1f3dd0d0e3aeb86146561b3d7e58656cbdbed1a39b91737b52ec7f2c
e758273c25fbad804fe884584e2797caefbbd1c2877dfd6f87ab1340cd25252e
3377a873db531113d79919e7a89369a79a602bac6ae09b9864b9378dc285f345
a3eb276fbd19dce2b00db6937578b214b9e33d67487659fe0bf21a86225ece73
a41670d52423ba69c7a65e7e153e7b9994e8dd0370c584bda0714bd61c49c578
54241ebe651a8344235cc47afd274c080abaebc8c3a25afb95d8373b6a5670a2
bbd37d41b7de6f93948fa2437a7699d4c30a3c39e736179702f212cb36a3133c
Domains
www.google.com
self.events.data.microsoft.com
crl.microsoft.com
slscr.update.microsoft.com
oneocsp.microsoft.com
settings-win.data.microsoft.com
uca2cb678a55183ecda1550afb7e.dl.dropboxusercontent.com
edge.microsoft.com
google.com
msedge.b.tlu.dl.delivery.mp.microsoft.com
nexusrules.officeapps.live.com
www.microsoft.com
api.edgeoffer.microsoft.com
config.edge.skype.com
th.bing.com
edge-cloud-resource-static.azureedge.net
www.bing.com
fe3cr.delivery.mp.microsoft.com
go.microsoft.com
oakgroverent.com
URLs
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/microsoft%20secure%20server%20ca%202026.crl
http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:fxn0hpxodx8qixxvpfvjtsb4g3ztcwtmfxac4p4avt0&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
https://edge.microsoft.com/serviceexperimentation/v3/?osname=win&channel=stable&osver=10.0.19045&devicefamily=desktop&installdate=1661339457&clientversion=133.0.3065.92&experimentationmode=2&scpguard=0&scpfull=0&scpver=0
https://config.edge.skype.com/config/v1/edge/133.0.3065.92?clientid=4489578223053569932&agents=edge%2cedgeconfig%2cedgeservices%2cedgefirstrun%2cedgefirstrunconfig&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=72&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1766137499&lafgdate=0
https://copilot.microsoft.com/c/api/user/eligibility
https://api.edgeoffer.microsoft.com/edgeoffer/pb/experiments?appid=edge-extensions&country=us
https://share.google/kckwqss7s6beypemy
https://www.google.com/share.google?q=kckwqss7s6beypemy
https://oakgroverent.com/ropeiud
https://oakgroverent.com/favicon.ico
https://www.bing.com/bloomfilterfiles/expandeddomainsfilterglobal.json
https://a.nel.cloudflare.com/report/v4?s=dpta1ykujievnebvjjeqz0n9vkeagsasngr5s3mvvuurbkflbrrtzen4qkruamvf%2fzrv%2fwngq505pixwqnaql6xyxsf8gqw8nlvjh8rurgee7i4uglpjh6l80q6wzecl6odc
https://config.edge.skype.com/config/v1/edge/133.0.3065.92?clientid=4489578223053569932&agents=edgeruntime%2cedgeruntimeconfig%2cedgedomainactions&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=72&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1789733132&lafgdate=0
https://xpaywalletcdn.azureedge.net/mswallet/expresscheckout/v1/getglobalconfig?edgechannel=stable&edgeversion=133.0.3065.92&configversion=0
https://oakgroverent.com/__slv
https://oakgroverent.com/ropeiud?__t=eyjrijoiccisimlwijoimtu4lje3my4xnjiuotuilcjhijoiuk9qzul1zcisim0iojasimv4cci6mtc4otczmziyndazmn0.ap8m-b0pdpv47y9isdy5kmo5gi_qory80med7xhxzls
https://www.dropbox.com/scl/fi/hp7c4p3l6j5mv2madjnf1/courrier_officiel_et_bordereau_de_pieces_-ref-fr2026-84920.zip?rlkey=1sfnttbccie9zt41jviup2s2o&st=ijlwefbe&dl=1
https://uca2cb678a55183ecda1550afb7e.dl.dropboxusercontent.com/cd/0/get/divvr9lcgxd4js0wh5hdfelbbdptjpc-r2pt10-aoju8zn19ysltmerucswrgjd2sg0iceloyjfc6bs7axazwajl7lzh2yf7t9jnf6ucecwblamt75cltef8h8joxnzvuwjbqjqopqkvytirdxcbytet/file?dl=1
https://edge.microsoft.com/extensionwebstorebase/v1/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=edgecrx&prodchannel=&prodversion=133.0.3065.92&lang=en-us&acceptformat=crx3,puff&x=id%3djmjflgjpcpepeafmmgdpfkogkghcpiha%26v%3d1.2.1%26installedby%3dother%26uc%26ping%3dr%253d273%2526e%253d1
Last Seen at

Recent blog posts

post image
Phishing Risk Across 5 Key US Industries: ANY...
watchers 3858
comments 0
post image
CSuite Targets US and EU Organizations with D...
watchers 9554
comments 0
post image
How MSSPs Can Prove Their Value When “Nothing...
watchers 8737
comments 0

What is Parallax RAT malware?

Parallax RAT, a remote access Trojan (RAT) active since December 2019. It has gained notoriety for its evasion techniques, such as process hollowing, and extensive data exfiltration capabilities.

The malware has been widely used by various APTs around the world, including in attacks during the COVID-19 pandemic. ParallaxRAT has also been linked to the activity of the advanced persistent threat (APT) named TA2541 that has been targeting aviation and defense industry actors since 2017.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

Technical details of the Parallax RAT malicious software

Parallax RAT’s architecture enables attackers to engage in diverse malicious activities. The most common of them are:

  • Credential theft: Steals login credentials from various sources, including cached passwords, browser cookies, and Windows credential stores.
  • Keystroke logging: Captures every keystroke typed on the infected machine, including passwords, messages, and other sensitive data.
  • Screen capture: Periodically or on-demand captures screenshots of the infected machine's desktop, providing the attacker with visual information about the user's activity.
  • Uploading and downloading of files: Allows the attacker to upload and download files to/from the infected machine.
  • Information gathering: Beyond basic system information (name, OS), Parallax RAT uses various techniques for extensive data exfiltration. This includes scraping clipboard content.

Similar to other malware families, such as WarzoneRAT and DarkGate, Parallax RAT utilizes a sophisticated process-hollowing technique. It injects its malicious payload into a legitimate Windows process (e.g., pipanel.exe), leveraging the process's existing privileges to bypass security checks and remain undetected.

The malware usually establishes persistence by adding itself to the startup folder and creating scheduled tasks. Afterwards, Parallax RAT opens communication channels with the attacker's command-and-control (C2) server. One of the standout features of the malware is the use of Windows Notepad for communication with the victim. In many instances, attackers used this way of connecting with the victims to instruct them to visit the criminals’ Telegram channel.

Parallax RAT often employs a multi-stage delivery chain to evade detection. Initial stages might involve seemingly harmless files like weaponized Microsoft Word documents with embedded macros. Triggering these macros can download and execute the next stage payload, often a malicious DLL.

Execution process of Parallax RAT

To see how Parallax RAT infection takes place and collect its indicators of compromise, we can use ANY.RUN. Let’s submit a PrallaxRAT sample for analysis.

Parallax utilizes various techniques to infect targeted systems and establish persistence within them. In our analysis, it's evident that this malware generates a child process that promptly initiates malicious activities, including the theft of personal data, execution of injected code in a separate process, and the creation of files in the startup directory. Parallax employs injection techniques to conceal itself within legitimate processes, rendering detection challenging. In this instance, it is injected into the Explorer.exe system process. Furthermore, the Remote Access Trojan (RAT) also establishes connections to a Command and Control (C2) server to receive additional instructions.

ParallaxRAT process graph shown in ANY.RUN ParallaxRAT's process graph demonstrated in ANY.RUN

Distribution methods of the Parallax RAT malware

Attackers that engage in the distribution of Parallax RAT typically leverage phishing campaigns. They use emails impersonating trusted entities (e.g., banks) with malicious attachments or links. For instance, during the COVID-19 pandemic, many ParallaxRAT campaigns involved sending victims messages with attached archives that contained files responsible for further infection of the victim’s device.

Conclusion

Parallax RAT's reliance on email-based social engineering makes it crucial for organizations to ensure that there are appropriate mechanisms in place to prevent infection. One of the essential elements of a layered defense strategy is a malware analysis sandbox. It offers an isolated environment for safely executing any file or opening a link to determine if it poses a danger.

ANY.RUN is a malware analysis sandbox that provides an effortless cloud-based experience for analyzing files and links. The service swiftly identifies ParallaxRAT and dozens of other malware families and provides users with conclusive reports on the threat, featuring the malware’s TTPs and IOCs.

Try ANY.RUN for free – request a demo!

HAVE A LOOK AT

Orcus RAT screenshot
Orcus RAT
orcus rat trojan
Orcus is a modular Remote Access Trojan with some unusual functions. This RAT enables attackers to create plugins using a custom development library and offers a robust core feature set that makes it one of the most dangerous malicious programs in its class.
Read More
Zloader screenshot
Zloader
zloader trojan loader
Zloader is a banking trojan that uses webinjects and VNC clients to still banking credentials. This Trojan is based on leaked code from 2011, but despite its age, Zloader’s popularity has been only increasing through early 2020, when it relied on COVID-19 themed attacks.
Read More
DarkTortilla screenshot
DarkTortilla
darktortilla
DarkTortilla is a crypter used by attackers to spread harmful software. It can modify system files to stay hidden and active. DarkTortilla is a multi-stage crypter that relies on several components to operate. It is often distributed through phishing sites that look like real services.
Read More
Bert Ransomware screenshot
Bert Ransomware is a newly emerged ransomware group that has been active since April 2025. It deploys variants targeting both Windows and Linux systems, focusing on critical sectors like healthcare, technology, and event services across the US, Asia, and Europe.
Read More
DarkVision screenshot
DarkVision
darkvision
DarkVision RAT is a low-cost, modular Remote Access Trojan that gives attackers remote control of infected Windows hosts. Initially observed around 2020 and sold in underground marketplaces, DarkVision has become notable for its full feature set (keylogging, screen capture, file theft, remote command execution and plugin support) and for being distributed via multi-stage loaders in recent campaigns.
Read More
GravityRAT screenshot
GravityRAT
gravity
GravityRAT is a sophisticated spyware and remote access trojan that has been actively targeting organizations and government entities since 2016. It uses innovative anti-analysis techniques and made an evolution from a Windows-only threat to a cross-platform espionage tool capable of compromising Windows, Android, and macOS systems.
Read More