166 terms · 75/46/45
Threat № 014 · class: malware

Remote access trojan - RAT

A RAT gives the attacker remote control of your machine. Once inside they can browse files, switch on the camera and microphone, record what you type and run commands — all of it live, as if sitting in front of your screen. It resembles remote support tools, only on the wrong side of the law.

Term

description · examples · notes

A RAT gives the attacker remote control of your machine. Once inside they can browse files, switch on the camera and microphone, record what you type and run commands — all of it live, as if sitting in front of your screen. It resembles remote support tools, only on the wrong side of the law.

Description

It usually arrives with Trojans and loaders, through an attachment, a crack or a fake installer. Because it allows interactive control, the attacker does not have to follow a script and can adapt as they go. Based on what they see, they choose the next move.

A RAT can be both surveillance and a staging point on the way to something worse. Through it the attacker can take your data, but can also wait for the right moment to move deeper into the network. Because it works interactively, it is more dangerous than malware programmed in advance for a fixed set of functions.

Examples

  • A Trojan from an email activates a RAT; the attacker has access to the machine for days, watching what happens and choosing what to do next.
  • Through a RAT the attacker can switch on the camera and microphone with no hint at all to the user.
  • A compromised machine with a RAT on it becomes the stepping stone to the rest of the network.

Notes

  • A RAT is not a script that does something and finishes — behind a RAT there is a person watching and adapting to what they find.
  • From the network side it shows up as a constant connection, or one at regular intervals, where no business reason accounts for it.

Mentioned in the news

Composite
Wikipedia

Techniques

carried out with 12

Defenses

countered by 8