RATAttack

First seen
2017-04-19 00:00:00
Malware type
rat
Family
Malware family
Profile updated
2026-07-07 15:41:42

Targeted industries: technology-and-telecommunications education-and-nonprofits government-and-public-sector

Context

RATAttack is a remote access trojan (RAT) that uses the Telegram protocol to support encrypted communication between the victim's machine and the attacker. The Telegram protocol also provides a simple method to communicate to the target, negating the need for port forwarding. Before using RATAttack, the attacker must create a Telegram bot and embed the bot's Telegram token into the trojan's configuration file. When a system is infected with RATAttack, it connects to the bot's Telegram channel. The attacker can then connect to the same channel and manage the RATAttack clients on the infected host machines. The trojan's code was available on GitHub then was taken down by the author on April 19, 2017.

Reports & references

  • cyber.nj.gov — Ratattack (report)

External references