SQLRat
MITRE ATT&CK: S0390 View on attack.mitre.org
Aliases: SQLRat
- First seen
- 2018-10-01 00:00:00
- Malware type
- rat
- Family
- Malware family
- Profile updated
- 2026-07-07 12:45:18
Targeted industries: financial-services retail-and-hospitality
Context
SQLRat is malware that executes SQL scripts to avoid leaving traditional host artifacts. FIN7 has been observed using it.
Detection coverage
- 369 Sigma rules
Malware & tools used
- File Deletion (attack-pattern)
- Windows Command Shell (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Malicious File (attack-pattern)
- Command Obfuscation (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- Scheduled Task (attack-pattern)
- PowerShell (attack-pattern)
Used by threat actors
- FIN7 (threat-actor)
Reports & references
- flashpoint-intel.com — Fin7 Revisited Inside Astra Panel And Sqlrat Malware (report)
- cert.ssi.gouv.fr — 20220427 Np Tlpwhite Anssi Fin7 (report)
- ti.qianxin.com — Cb78386A082F465F259B37Dae5Df4884 (report)
- malpedia.caad.fkie.fraunhofer.de — Js.Sqlrat (report)
- MITRE ATT&CK — S0390 (report)