Proton RAT

Aliases: Calisto

First seen
2017-03-01 00:00:00
Malware type
rat, credential-stealer, keylogger, spyware
Family
Malware family
Last IoC activity
2026-07-13 05:48:36
Profile updated
2026-07-07 14:37:33

Targeted industries: technology-and-telecommunications financial-services

Context

Proton RAT is a Remote Access Trojan (RAT) specifically designed for macOS systems. It is known for providing attackers with complete remote control over the infected system, allowing the execution of commands, keystroke capturing, access to the camera and microphone, and the ability to steal credentials stored in browsers and other password managers. This malware typically spreads through malicious or modified applications, which, when downloaded and installed by unsuspecting users, trigger its payload. Proton RAT is notorious for its sophistication and evasion capabilities, including techniques to bypass detection by installed security solutions.

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Osx.Proton Rat (report)
  • threatpost.com — 125518 (report)
  • objective-see.com — Blog 0X1F (report)
  • Kaspersky — 86543 (report)
  • cybersixgill.com — 02072017%20 %20Proton%20 %20A%20New%20Mac%20Os%20Rat%20 %20Sixgill%20Threat%20Report (report)
  • blog.malwarebytes.com — Osx Proton Spreading Through Fake Symantec Blog (report)
  • cybereason.com — Labs Proton B What This Mac Malware Actually Does (report)
  • ESET — Osx Proton Supply Chain Attack Elmedia (report)
  • hackread.com — Hackers Selling Undetectable Proton Mac Malware (report)
  • objective-see.com — Blog 0X1D (report)

External references