TrustConnect RAT

First seen
2022-05-10 00:00:00
Malware type
rat, screen-capture
Family
Malware family
Profile updated
2026-07-07 15:23:31

Targeted industries: government-and-public-sector healthcare-and-pharmaceutical financial-services

Context

TrustConnect RAT is a malware-as-a-service remote access trojan disguised as a legitimate remote monitoring tool. It gives attackers full control of infected systems through a web dashboard, allowing them to manage compromised devices, run commands, transfer files, collect system data, initiate remote desktop sessions, and record screens via standard SSL/TLS-protected web APIs. DocConnect RAT is an upgraded and reengineered version of TrustConnect RAT. It fixes earlier security and detection weaknesses (such as poor credential storage, weak persistence, and detectable command-and-control mechanisms) while adding new capabilities, including an interactive multi-session terminal, stronger process protection against termination, a fake Windows Update overlay for deception, and a PDF-based lure and delivery system.

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Trustconnect (report)
  • Microsoft — Signed Malware Impersonating Workplace Apps Deploys Rmm Backdoors (report)
  • proofpoint.com — Dont Trustconnect Its A Rat (report)

External references