FatalRat
Aliases: Sainbox RAT
- Malware type
- rat, keylogger
- Family
- Malware family
- Last IoC activity
- 2026-07-22 00:38:21
- Profile updated
- 2026-07-07 14:57:54
Targeted industries: financial-services government-and-public-sector technology-and-telecommunications
Context
FatalRAT is a most-likely chinese remote access tool distributed through forums and Telegram channels. FatalRAT executes various anti-virtual machine tests to avoid detection before fully infecting systems. Upon successful infiltration, it decrypts configuration strings, disables the CTRL+ALT+DELETE function, and activates a keylogger. The malware can establish persistence via registry modifications or service creation, collect sensitive data, and communicate with its command and control (C&C) server using encrypted methods. FatalRAT also employs techniques like brute-force attacks against weak passwords to propagate within networks.
Detection coverage
- 1 YARA rules
Detection rules
- DITEKSHEN_MALWARE_Win_Fatalrat (yara-rule)
Reports & references
- thehackernews.com — Purple Fox Hackers Spotted Using New (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Fatal Rat (report)
- proofpoint.com — Chinese Malware Appears Earnest Across Cybercrime Threat Landscape (report)
- youtube.com — Watch (report)
- Trend Micro — Purple Fox Uses New Arrival Vector And Improves Malware Arsenal (report)
- cybersecurity.att.com — New Sophisticated Rat In Town Fatalrat Analysis (report)