CrossRAT

MITRE ATT&CK: S0235 View on attack.mitre.org

Aliases: Trupto, CrossRAT

First seen
2018-01-01 00:00:00
Malware type
rat
Family
Malware family
Operating systems
linux, windows, macos
Related IoCs
8 (8 malicious)
Last IoC activity
2026-08-17 09:27:43
Profile updated
2026-07-07 12:52:28

Context

CrossRAT is a cross-platform remote access tool (RAT) that affects Windows, OSX, and Linux systems. It is known for its ability to provide attackers with remote control over infected devices.

Recent IoC activity

9 malicious indicators in Maltiverse are attributed to CrossRAT (S0235). The 9 most recently updated:

Detection coverage

  • 64 Sigma rules

Malware & tools used

  • Screen Capture (attack-pattern)
  • Launch Agent (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • XDG Autostart Entries (attack-pattern)

Used by threat actors

Reports & references

  • info.lookout.com — Lookout Dark Caracal Srr 20180118 Us V.1.0 (report)
  • malpedia.caad.fkie.fraunhofer.de — Jar.Crossrat (report)
  • objective-see.com — Blog 0X28 (report)
  • MITRE ATT&CK — S0235 (report)
  • digitasecurity.com — Crossrat (report)

External references