Skip to content

ProRat

ProRat is a Windows remote access trojan from the early 2000s associated with the PRO Group.

Profile source: Mallory opens in a new tab

ProRat

Family profile

ProRat is a Windows remote access trojan from the early 2000s associated with the PRO Group. It is an established legacy RAT family that uses a client-server architecture in which a victim-side payload provides unauthorized remote access to an attacker-controlled controller application. ProRat belongs to the generation of commercialized and black-hat RAT tooling that expanded on earlier families by combining remote administration features with persistence and extensibility.

ProRat is designed to give an operator covert control over an infected system. Reported capabilities include remote system access, file browsing and transfer, screenshot-related functionality, and support for remote plugins that can be uploaded and executed on compromised hosts. Analysis of the malware has shown that its protocol uses command identifiers and separate ports for different functions, including file upload and plugin handling. Its communications have been observed in plaintext, making the protocol susceptible to interception and abuse. Reverse engineering has also shown that the payload was packed with UPX and that the malware can establish persistence on Windows through filesystem and registry modifications.

As a RAT family, ProRat fits the broader pattern of malware used for unauthorized surveillance and post-compromise control, including theft of credentials and other sensitive user data, monitoring of victim activity, and execution of additional payloads. Legacy RATs of this class were commonly distributed through social engineering and malicious downloads, including crafted email attachments, malicious links, bundled download packages, and torrent-distributed lures. ProRat is primarily associated with Windows systems and is historically notable as one of the better-known RAT families of the 2000s era.

Capabilities

  • Credential Theft
  • Exfiltration
  • Persistence
  • Post Exploitation

MITRE ATT&CK

ProRat in ATT&CK

8 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.