Skip to content

CyberGate

Also known as: Rebhip

According to Subex Secure, CyberGate is a Remote Access Trojan (RAT) that allows an attacker to gain unauthorized access to

the victim’s system. Attackers can remotely connect to the compromised system from anywhere

around the world. The Malware author generally uses this program to steal private information

like passwords, files, etc. It might also be used to install malicious software on the compromised

systems.

C2 Infrastructure

Hosting/VPS 67%
ISP/Residential 33%

Last 7 days

Jun 4, 2026
C2 Hosts: 3

Further Reading

RL Blog | ReversingLabs opens in a new tab

RL Blog: AppSec & Supply Chain Security, Dev & DevSecOps, Threat Research, and Security Operations (SecOps)

blog.reversinglabs.com
Packrat: Seven Years of a South American Threat Actor opens in a new tab

Report uncovering a South American group targeting politicians, journalists, and civil society with malware campaigns, phishing, and elaborate fake organizations.

citizenlab.ca
Ten process injection techniques: A technical survey of common and trending process injection techniques opens in a new tab

Process injection is a widespread defense evasion technique employed often within malware and fileless adversary tradecraft, and entails running custom code within the address space of another proc...

elastic.co
Ten process injection techniques: A technical survey of common and trending process injection techniques opens in a new tab

Process injection is a widespread defense evasion technique employed often within malware and fileless adversary tradecraft, and entails running custom code within the address space of another proc...

endgame.com
Analysis of top non-HTTP/S threats | Zscaler Blog opens in a new tab

In this article, Zscaler security research team dissect the custom protocols used in some of the most prevalent RATs seen in recent campaigns. Read more.

zscaler.com
CyberGate, RedLine Part of AutoIt Malware Campaign| Zscaler opens in a new tab

The CyberGate RAT and RedLine stealer are being delivered in ongoing campaign using the AutoIt malware. Read more.

zscaler.com