Skip to content

FatalRAT

FatalRAT is a Windows remote access trojan written in C++ and associated with multiple Chinese-speaking intrusion and crimeware ecosystems, including activity linked to Purple Fox and campaigns assessed as China-nexus targeting organizations in the Asia-Pacific region.

Profile source: Mallory opens in a new tab

FatalRAT

Family profile

FatalRAT is a Windows remote access trojan written in C++ and associated with multiple Chinese-speaking intrusion and crimeware ecosystems, including activity linked to Purple Fox and campaigns assessed as China-nexus targeting organizations in the Asia-Pacific region. It has been observed in continuously updated variants and is often deployed as part of multi-stage infection chains rather than as a standalone initial payload.

FatalRAT provides remote command execution and system control, establishes command-and-control communications, fingerprints infected hosts, and can exfiltrate sensitive information. Reported variants load auxiliary modules conditionally based on victim-environment checks such as the presence of antivirus software or other host characteristics, allowing operators to tailor post-compromise behavior. Documented overlaps with older malware clusters indicate code reuse and shared tradecraft, including functionality associated with keylogging and broader surveillance-oriented collection.

Observed delivery has included trojanized software installers masquerading as legitimate applications, poisoned search-engine results leading users to fake downloads, phishing campaigns, and DLL sideloading. In Purple Fox-linked activity, malicious installers acted as first-stage loaders that retrieved second-stage archives and memory-loaded a FatalRAT-derived payload using custom shellcode loaders designed to minimize forensic artifacts. Some campaigns also paired FatalRAT with signed kernel drivers, rootkit components, and antivirus-evasion modules to disable or bypass security controls.

FatalRAT activity has targeted Chinese-language users in Southeast and East Asia as well as government and corporate networks in APAC. It has also been associated with lateral movement behavior in some reporting, including brute-force attempts against network shares and remote propagation after successful authentication. The malware is best characterized as a modular RAT used for persistent remote access, data theft, and follow-on intrusion activity on compromised Windows systems.

Capabilities

  • Brute Force
  • Defense Evasion
  • Dll Sideloading
  • Exfiltration
  • Keylogging
  • Lateral Movement
  • Persistence
  • Post Exploitation
  • Reconnaissance

Reported operators

Threat actors

1 named in public reporting
Silver Fox

45.192.219.135 — a Hong Kong VPS on Antbox Networks Limited (AS138995) that plays double duty as: FatalRAT C2 backend — tied to a live campaign deploying FatalRAT, Winos4.0, and QQHong sideloaded via Sogou Input Method DLL sideloading (ManualNewWord.dll), VMProtect-packed, beaconing on port 1080 + HTTPS cover on 443...

MITRE ATT&CK

FatalRAT in ATT&CK

24 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.