BreachRAT

First seen
2021-05-10 00:00:00
Malware type
rat, backdoor
Family
Malware family
Profile updated
2026-07-07 12:47:44

Targeted industries: government-and-public-sector technology-and-telecommunications

Context

This is a backdoor which FireEye call the Breach Remote Administration Tool (BreachRAT), written in C++. The malware name is derived from the hardcoded PDB path found in the RAT: C:\Work\Breach Remote Administration Tool\Release\Client.pdb

Reports & references

  • Mandiant — Apt Group Sends Spea (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Breach Rat (report)

External references