EpicSplit RAT

Malware type
rat, screen-capture
Family
Malware family
Profile updated
2026-07-07 14:32:06

Targeted industries: technology-and-telecommunications

Context

EpicSplit RAT is a multiplatform Java RAT that is capable of running shell commands, downloading, uploading, and executing files, manipulating the file system, establishing persistence, taking screenshots, and manipulating keyboard and mouse events. EpicSplit is typically obfuscated with the commercial Allatori Obfuscator software. One unique feature of the malware is that TCP messages sent by EpicSplit RAT to its C2 are terminated with the string "_packet_" as a packet delimiter.

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Jar.Epicsplit (report)
  • zscaler.com — Targeted Attacks Indian Government And Financial Institutions Using Jsoutprox Rat (report)

External references