Last seven days
- First activity
- Aug 14, 2026
- Last activity
- Aug 14, 2026
- Feed role
- C2
- Host form
- 0 IP / 1 hostnames
SparkRAT is an open-source, Go-based remote access trojan used as a cross-platform backdoor on Windows, Linux, and macOS.
Profile source: Mallory opens in a new tabSparkRAT
SparkRAT is an open-source, Go-based remote access trojan used as a cross-platform backdoor on Windows, Linux, and macOS. It has been observed in both opportunistic and targeted intrusions, including exploitation of internet-facing enterprise software, supply-chain-style compromises involving trojanized installers, and campaigns associated with Chinese-speaking operators. Reported use includes the DragonSpark intrusion cluster, compromises involving vulnerable TeamCity and BeyondTrust systems, activity linked to Houken/UNC5174 tradecraft, and malware delivery through compromised VPN software and malicious Windows shortcut-based infection chains targeting organizations in Ukraine.
SparkRAT provides full remote administration capabilities, including command execution, file upload and download, process management, system fingerprinting, screenshot capture, and collection of host information. Public reporting also describes support for encrypted command-and-control communications, including WebSocket-based communications, and an automatic upgrade mechanism in some versions. Operators have used distinct per-target builds, and both x86 and x64 Windows variants have been observed.
In observed attack chains, SparkRAT has commonly served as a post-compromise backdoor rather than an initial access tool. Delivery has followed exploitation of public-facing vulnerabilities, malicious installers that also execute legitimate software to reduce suspicion, and downloader or dropper stages that unpack and launch the RAT. Persistence has been established through mechanisms such as scheduled tasks and startup execution. SparkRAT has also been deployed alongside other offensive tooling and malware families including Cobalt Strike, Sliver, web shells, tunneling tools, ransomware, cryptominers, and credential-focused tooling, indicating its role as a flexible access and control component in broader intrusion operations.
Although SparkRAT is publicly available and used by multiple unrelated actors, several campaigns involving it show overlap with Chinese-language tooling ecosystems and Chinese-speaking operators. Its open-source nature and cross-platform support have made it attractive for reuse across espionage, initial-access, and financially motivated operations.
C2 tracking
Derp observations, rolling seven-day window
Samples
Reported operators
The other files detected exploiting the new vulnerability followed a similar attack scenario that ended with the installation of Redline Stealer malware. The similarity has two possible explanations: 1. One attacker using different types of malware (the initial file installs SparkRAT malware).
The following public tools were observed on the victims’ network... SparkRAT.
Sandbox family search for family:sparkrat . Returned a per-victim SparkRAT sibling submitted independently to the sandbox. Its ldflags COMMIT differs from the case sample. Confirms the operator uses per-target SparkRAT builds.
...Leslieloader that downloads a backdoor dubbed SparkRAT. The Go variants are compliant with Windows, Linux and OSX. They support file upload and download, system fingerprinting and direct command-line interaction with infected hosts.
"...including CurlBack, SparkRAT, AresRAT, Xeno RAT, AllaKore, and ReverseRAT."
The attacks are characterized by the use of the little known open source SparkRAT and malware that attempts to evade detection through Golang source code interpretation.
...UNK_ColtCentury... likely an attempt to deploy the SparkRAT backdoor.
"CVE-2026-1731 (BeyondTrust) is associated with HAFNIUM and linked to Lumma Stealer, SparkRAT, and VShell malware deployments."
“The primary C2 frameworks observed were Cobalt Strike, VShell, Havoc, Sliver, and SparkRat.”
Exploited software
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.