GodRAT

Malware type
rat
Family
Malware family
Last IoC activity
2026-04-12 11:06:29
Profile updated
2026-07-07 15:03:18

Targeted industries: government-and-public-sector technology-and-telecommunications defense-and-aerospace

Context

GodRAT shares a common origin with AwesomePuppet RAT, alongside Gh0st RAT code similarities. GodRAT is likely connected with Winnty APT activities. Old implant codebases, such as Gh0st RAT, which are nearly two decades old, continue to be used today. These are often customized and rebuilt to target a wide range of victims. These old implants are known to have been used by various threat actors for a long time, and the GodRAT discovery demonstrates that legacy codebases like Gh0st RAT can still maintain a long lifespan in the cybersecurity landscape.

Detection coverage

  • 1 YARA rules

Detection rules

  • SIGNATURE_BASE_MAL_CRIME_RAT_WIN_PE_Godrat_Aug25 (yara-rule)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Godrat (report)
  • Kaspersky — 117119 (report)

External references