Borat RAT
- Malware type
- rat, spyware, ransomware, keylogger, credential-stealer
- Family
- Malware family
- Last IoC activity
- 2026-07-15 16:04:29
- Profile updated
- 2026-07-07 14:50:15
Context
The Borat RAT comes bundled with its components (e.g. binary builder, supporting modules, server certificates). According to Cyble this malware is an unique combination of RAT, Spyware, and ransomware. The supporting modules are included; a few of the capabilities: Keylogger, Ransomware, Audio/Webcam Recording, Process Hollowing, Browser Credential/Discord Token Stealing, etc.
Detection coverage
- 1 YARA rules
Detection rules
- SEKOIA_Rat_Win_Borat (yara-rule)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Boratrat (report)
- blog.cyble.com — Deep Dive Analysis Borat Rat (report)
- blogs.blackberry.com — Threat Thursday Boratrat (report)
- bleepingcomputer.com — New Borat Remote Access Malware Is No Laughing Matter (report)