GobRAT

First seen
2022-05-01 00:00:00
Malware type
rat
Family
Malware family
Last IoC activity
2026-07-21 21:00:32
Profile updated
2026-07-07 14:25:15

Targeted industries: government-and-public-sector technology-and-telecommunications

Targeted regions: country_code:jp

Context

GobRAT is a remote access trojan that has been identified targeting entities primarily in Japan. It is employed for cyber espionage purposes, capable of maintaining persistence and executing arbitrary commands on compromised systems.

Detection coverage

  • 3 YARA rules

Detection rules

  • DITEKSHEN_MALWARE_Linux_Gobrat (yara-rule)
  • SEKOIA_Rat_Lin_Gobrat_2023 (yara-rule)
  • SEKOIA_Apt_Gobrat_2 (yara-rule)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Elf.Gobrat (report)
  • blogs.jpcert.or.jp — Gobrat (report)

External references