RATel

First seen
2021-05-15 00:00:00
Malware type
rat
Family
Malware family
Last IoC activity
2026-07-22 00:35:41
Profile updated
2026-07-07 13:12:37

Targeted industries: government-and-public-sector financial-services technology-and-telecommunications

Context

RATel is a remote access tool (RAT) utilized in cyber espionage campaigns. It primarily targets government sectors and financial services, enabling attackers to gain unauthorized access to target systems.

Detection coverage

  • 2 YARA rules

Used by threat actors

  • MacroPack Payload Delivery Activity (campaign)

Exploited vulnerabilities

  • CVE-2022-47966 (vulnerability)

Detection rules

  • SEKOIA_Rat_Win_Ratel_Strings (yara-rule)
  • MALPEDIA_Win_Ratel_Auto (yara-rule)

Reports & references

  • Kaspersky — 109552 (report)
  • businessinsights.bitdefender.com — Tech Advisory Manageengine Cve 2022 47966 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Ratel (report)
  • github.com — Ratel (report)

External references