FatalRat

Aliases: Sainbox RAT

Malware type
rat, keylogger
Family
Malware family
Last IoC activity
2026-07-22 00:38:21
Profile updated
2026-07-07 14:57:54

Targeted industries: financial-services government-and-public-sector technology-and-telecommunications

Context

FatalRAT is a most-likely chinese remote access tool distributed through forums and Telegram channels. FatalRAT executes various anti-virtual machine tests to avoid detection before fully infecting systems. Upon successful infiltration, it decrypts configuration strings, disables the CTRL+ALT+DELETE function, and activates a keylogger. The malware can establish persistence via registry modifications or service creation, collect sensitive data, and communicate with its command and control (C&C) server using encrypted methods. FatalRAT also employs techniques like brute-force attacks against weak passwords to propagate within networks.

Detection coverage

  • 1 YARA rules

Detection rules

  • DITEKSHEN_MALWARE_Win_Fatalrat (yara-rule)

Reports & references

  • thehackernews.com — Purple Fox Hackers Spotted Using New (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Fatal Rat (report)
  • proofpoint.com — Chinese Malware Appears Earnest Across Cybercrime Threat Landscape (report)
  • youtube.com — Watch (report)
  • Trend Micro — Purple Fox Uses New Arrival Vector And Improves Malware Arsenal (report)
  • cybersecurity.att.com — New Sophisticated Rat In Town Fatalrat Analysis (report)

External references