45.192.219.135 — a Hong Kong VPS on Antbox Networks Limited (AS138995) that plays double duty as: FatalRAT C2 backend — tied to a live campaign deploying FatalRAT, Winos4.0, and QQHong sideloaded via Sogou Input Method DLL sideloading (ManualNewWord.dll), VMProtect-packed, beaconing on port 1080 + HTTPS cover on 443...
FatalRAT
FatalRAT is a Windows remote access trojan written in C++ and associated with multiple Chinese-speaking intrusion and crimeware ecosystems, including activity linked to Purple Fox and campaigns assessed as China-nexus targeting organizations in the Asia-Pacific region.
Profile source: Mallory opens in a new tabFatalRAT
Family profile
FatalRAT is a Windows remote access trojan written in C++ and associated with multiple Chinese-speaking intrusion and crimeware ecosystems, including activity linked to Purple Fox and campaigns assessed as China-nexus targeting organizations in the Asia-Pacific region. It has been observed in continuously updated variants and is often deployed as part of multi-stage infection chains rather than as a standalone initial payload.
FatalRAT provides remote command execution and system control, establishes command-and-control communications, fingerprints infected hosts, and can exfiltrate sensitive information. Reported variants load auxiliary modules conditionally based on victim-environment checks such as the presence of antivirus software or other host characteristics, allowing operators to tailor post-compromise behavior. Documented overlaps with older malware clusters indicate code reuse and shared tradecraft, including functionality associated with keylogging and broader surveillance-oriented collection.
Observed delivery has included trojanized software installers masquerading as legitimate applications, poisoned search-engine results leading users to fake downloads, phishing campaigns, and DLL sideloading. In Purple Fox-linked activity, malicious installers acted as first-stage loaders that retrieved second-stage archives and memory-loaded a FatalRAT-derived payload using custom shellcode loaders designed to minimize forensic artifacts. Some campaigns also paired FatalRAT with signed kernel drivers, rootkit components, and antivirus-evasion modules to disable or bypass security controls.
FatalRAT activity has targeted Chinese-language users in Southeast and East Asia as well as government and corporate networks in APAC. It has also been associated with lateral movement behavior in some reporting, including brute-force attempts against network shares and remote propagation after successful authentication. The malware is best characterized as a modular RAT used for persistent remote access, data theft, and follow-on intrusion activity on compromised Windows systems.
Capabilities
- Brute Force
- Defense Evasion
- Dll Sideloading
- Exfiltration
- Keylogging
- Lateral Movement
- Persistence
- Post Exploitation
- Reconnaissance
Reported operators
Threat actors
1 named in public reportingMITRE ATT&CK