BlackRemote
Aliases: BlackRAT
- First seen
- 2022-08-15 00:00:00
- Malware type
- rat
- Family
- Malware family
- Last IoC activity
- 2026-07-15 02:47:50
- Profile updated
- 2026-07-07 14:43:09
Targeted industries: government-and-public-sector financial-services technology-and-telecommunications
Context
BlackRemote, also known as BlackRAT, is a remote access tool used primarily for espionage activities. It enables attackers to gain unauthorized access to victim systems to steal sensitive information and monitor user activities.
Detection coverage
- 2 YARA rules
Detection rules
- DITEKSHEN_MALWARE_Win_Validalpha (yara-rule)
- SEKOIA_Backdoor_Win_Blackrat (yara-rule)
Reports & references
- news.sophos.com — Raticate (report)
- asec.ahnlab.com — 56405 (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Blackremote (report)
- unit42.paloaltonetworks.jp — Blackremote Money Money Money A Swedish Actor Peddles An Expensive New Rat (report)
- Palo Alto Unit 42 — Blackremote Money Money Money A Swedish Actor Peddles An Expensive New Rat (report)