BreachRAT
- First seen
- 2021-05-10 00:00:00
- Malware type
- rat, backdoor
- Family
- Malware family
- Profile updated
- 2026-07-07 12:47:44
Targeted industries: government-and-public-sector technology-and-telecommunications
Context
This is a backdoor which FireEye call the Breach Remote Administration Tool (BreachRAT), written in C++. The malware name is derived from the hardcoded PDB path found in the RAT: C:\Work\Breach Remote Administration Tool\Release\Client.pdb
Reports & references
- Mandiant — Apt Group Sends Spea (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Breach Rat (report)