RATel
- First seen
- 2021-05-15 00:00:00
- Malware type
- rat
- Family
- Malware family
- Last IoC activity
- 2026-07-22 00:35:41
- Profile updated
- 2026-07-07 13:12:37
Targeted industries: government-and-public-sector financial-services technology-and-telecommunications
Context
RATel is a remote access tool (RAT) utilized in cyber espionage campaigns. It primarily targets government sectors and financial services, enabling attackers to gain unauthorized access to target systems.
Detection coverage
- 2 YARA rules
Used by threat actors
- MacroPack Payload Delivery Activity (campaign)
Exploited vulnerabilities
- CVE-2022-47966 (vulnerability)
Detection rules
- SEKOIA_Rat_Win_Ratel_Strings (yara-rule)
- MALPEDIA_Win_Ratel_Auto (yara-rule)
Reports & references
- Kaspersky — 109552 (report)
- businessinsights.bitdefender.com — Tech Advisory Manageengine Cve 2022 47966 (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Ratel (report)
- github.com — Ratel (report)