Sorillus RAT
- First seen
- 2019-01-01 00:00:00
- Malware type
- rat
- Family
- Malware family
- Last IoC activity
- 2026-07-21 04:31:16
- Profile updated
- 2026-07-07 14:32:26
Context
Sorillus is a Java-based multifunctional remote access trojan (RAT) that targets Linux, macOS, and Windows operating systems. First created in 2019, the tool gained significant attention in 2022 when various obfuscated client versions began appearing on VirusTotal starting January 18, 2022. The RAT's features were detailed on its now-defunct website (hxxps://sorillus[.]com), where it was marketed for lifetime access at 59.99€, with a discounted price of 19.99€ at the time. Payments were conveniently accepted via various cryptocurrencies. The creator and distributor of Sorillus, a YouTube user known as "Tapt," claimed the tool could collect sensitive information from infected systems, including: HardwareID Username Country Language Webcam footage Headless status Operating system details Client version However, Sorillus was shut down in 2025 following the FBI's Operation "Talent," which targeted alot of the Cracking infrastucture which included Sellix, the payment portal used by Sorillus for transactions. This operation disrupted the financial infrastructure supporting the RAT, leading to its cessation of operations 5 days later.
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Jar.Sorillus (report)
- abnormalsecurity.com — Tax Customers Sorillus Rat (report)
- orangecyberdefense.com — From Sambaspy To Sorillus Dancing Through A Multi Language Phishing Campaign In Europe (report)