Borat RAT

Malware type
rat, spyware, ransomware, keylogger, credential-stealer
Family
Malware family
Last IoC activity
2026-07-15 16:04:29
Profile updated
2026-07-07 14:50:15

Context

The Borat RAT comes bundled with its components (e.g. binary builder, supporting modules, server certificates). According to Cyble this malware is an unique combination of RAT, Spyware, and ransomware. The supporting modules are included; a few of the capabilities: Keylogger, Ransomware, Audio/Webcam Recording, Process Hollowing, Browser Credential/Discord Token Stealing, etc.

Detection coverage

  • 1 YARA rules

Detection rules

  • SEKOIA_Rat_Win_Borat (yara-rule)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Boratrat (report)
  • blog.cyble.com — Deep Dive Analysis Borat Rat (report)
  • blogs.blackberry.com — Threat Thursday Boratrat (report)
  • bleepingcomputer.com — New Borat Remote Access Malware Is No Laughing Matter (report)

External references