RunningRAT
MITRE ATT&CK: S0253 View on attack.mitre.org
Aliases: RunningRAT
- First seen
- 2018-02-01 00:00:00
- Malware type
- rat
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 31 (31 malicious)
- Last IoC activity
- 2026-09-01 08:36:37
- Profile updated
- 2026-07-07 15:18:48
Targeted industries: government-and-public-sector media-and-entertainment
Targeted regions: country_code:kr
Context
RunningRAT is a remote access tool that appeared in operations surrounding the 2018 Pyeongchang Winter Olympics along with Gold Dragon and Brave Prince.
Recent IoC activity
31 malicious indicators in Maltiverse are attributed to RunningRAT (S0253). The 20 most recently updated:
Detection coverage
- 1 YARA rules
- 275 Sigma rules
Malware & tools used
- Local Storage Discovery (attack-pattern)
- Disable or Modify Tools (attack-pattern)
- Windows Command Shell (attack-pattern)
- Keylogging (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- File Deletion (attack-pattern)
- System Information Discovery (attack-pattern)
- Archive Collected Data (attack-pattern)
- Clear Windows Event Logs (attack-pattern)
- Clipboard Data (attack-pattern)
Detection rules
- MALPEDIA_Win_Runningrat_Auto (yara-rule)
Reports & references
- McAfee — Gold Dragon Widens Olympics Malware Attacks Gains Permanent Presence On Victims Systems (report)
- MITRE ATT&CK — S0253 (report)