CrossRAT
MITRE ATT&CK: S0235 View on attack.mitre.org
Aliases: Trupto, CrossRAT
- First seen
- 2018-01-01 00:00:00
- Malware type
- rat
- Family
- Malware family
- Operating systems
- linux, windows, macos
- Related IoCs
- 8 (8 malicious)
- Last IoC activity
- 2026-08-17 09:27:43
- Profile updated
- 2026-07-07 12:52:28
Context
CrossRAT is a cross-platform remote access tool (RAT) that affects Windows, OSX, and Linux systems. It is known for its ability to provide attackers with remote control over infected devices.
Recent IoC activity
9 malicious indicators in Maltiverse are attributed to CrossRAT (S0235). The 9 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| file sample | c0762bd8b3b098c6d5300256f9e8bc67d45709dc244db.exe | 2026-09-02 | 4 |
| file sample | f35b6cb6af991bfa735e039f6bc0e49c69759c015a207.exe | 2026-08-17 | 4 |
| file sample | 737646392a7c882064e22ecb9fc0b2732399e44ced2f56d873e656d0035af288.bin | 2026-08-11 | 4 |
| file sample | 66lottery.exe | 2026-08-09 | 4 |
| file sample | ekstre.pdf.exe | 2026-08-09 | 4 |
| file sample | _6eaa4e25359d0b61c37a9884fbdb8c53bf00e8e9a5478e325e63338d0d2ad51b.exe | 2026-08-08 | 4 |
| file sample | 40079f05ba7cdccac1f62f8e7e1b644bc0a806b58465f5c005725bc54ee73ef1.exe | 2026-08-01 | 4 |
| file sample | vwExeNX.exe | 2026-07-18 | 4 |
| file sample | 1f5fd302317ab14f751695ee07a4901d1b7319641181eaeabe3c14cf46ec9525 | 2026-05-08 | 1 |
Detection coverage
- 64 Sigma rules
Malware & tools used
- Screen Capture (attack-pattern)
- Launch Agent (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- XDG Autostart Entries (attack-pattern)
Used by threat actors
- Dark Caracal (threat-actor)
Reports & references
- info.lookout.com — Lookout Dark Caracal Srr 20180118 Us V.1.0 (report)
- malpedia.caad.fkie.fraunhofer.de — Jar.Crossrat (report)
- objective-see.com — Blog 0X28 (report)
- MITRE ATT&CK — S0235 (report)
- digitasecurity.com — Crossrat (report)