GopherRAT

First seen
2020-06-15 00:00:00
Malware type
rat
Family
Malware family
Profile updated
2026-07-07 15:03:51

Targeted industries: technology-and-telecommunications government-and-public-sector

Targeted regions: country_code:in country_code:pk

Context

GopherRAT is a remote access trojan known for its use in cyber espionage activities targeting organizations primarily in India and Pakistan. It is capable of providing attackers with remote administrative control over compromised systems.

Detection coverage

  • 1 YARA rules

Detection rules

  • WITHSECURELABS_Andariel_Gopherrat (yara-rule)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Gopher Rat (report)
  • labs.withsecure.com — Withsecure Andariel 2025 (report)

External references