GobRAT
- First seen
- 2022-05-01 00:00:00
- Malware type
- rat
- Family
- Malware family
- Last IoC activity
- 2026-07-21 21:00:32
- Profile updated
- 2026-07-07 14:25:15
Targeted industries: government-and-public-sector technology-and-telecommunications
Targeted regions: country_code:jp
Context
GobRAT is a remote access trojan that has been identified targeting entities primarily in Japan. It is employed for cyber espionage purposes, capable of maintaining persistence and executing arbitrary commands on compromised systems.
Detection coverage
- 3 YARA rules
Detection rules
- DITEKSHEN_MALWARE_Linux_Gobrat (yara-rule)
- SEKOIA_Rat_Lin_Gobrat_2023 (yara-rule)
- SEKOIA_Apt_Gobrat_2 (yara-rule)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Elf.Gobrat (report)
- blogs.jpcert.or.jp — Gobrat (report)