BlackRemote

Aliases: BlackRAT

First seen
2022-08-15 00:00:00
Malware type
rat
Family
Malware family
Last IoC activity
2026-07-15 02:47:50
Profile updated
2026-07-07 14:43:09

Targeted industries: government-and-public-sector financial-services technology-and-telecommunications

Context

BlackRemote, also known as BlackRAT, is a remote access tool used primarily for espionage activities. It enables attackers to gain unauthorized access to victim systems to steal sensitive information and monitor user activities.

Detection coverage

  • 2 YARA rules

Detection rules

  • DITEKSHEN_MALWARE_Win_Validalpha (yara-rule)
  • SEKOIA_Backdoor_Win_Blackrat (yara-rule)

Reports & references

  • news.sophos.com — Raticate (report)
  • asec.ahnlab.com — 56405 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Blackremote (report)
  • unit42.paloaltonetworks.jp — Blackremote Money Money Money A Swedish Actor Peddles An Expensive New Rat (report)
  • Palo Alto Unit 42 — Blackremote Money Money Money A Swedish Actor Peddles An Expensive New Rat (report)

External references