TrustConnect RAT
- First seen
- 2022-05-10 00:00:00
- Malware type
- rat, screen-capture
- Family
- Malware family
- Profile updated
- 2026-07-07 15:23:31
Targeted industries: government-and-public-sector healthcare-and-pharmaceutical financial-services
Context
TrustConnect RAT is a malware-as-a-service remote access trojan disguised as a legitimate remote monitoring tool. It gives attackers full control of infected systems through a web dashboard, allowing them to manage compromised devices, run commands, transfer files, collect system data, initiate remote desktop sessions, and record screens via standard SSL/TLS-protected web APIs. DocConnect RAT is an upgraded and reengineered version of TrustConnect RAT. It fixes earlier security and detection weaknesses (such as poor credential storage, weak persistence, and detectable command-and-control mechanisms) while adding new capabilities, including an interactive multi-session terminal, stronger process protection against termination, a fake Windows Update overlay for deception, and a PDF-based lure and delivery system.
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Trustconnect (report)
- Microsoft — Signed Malware Impersonating Workplace Apps Deploys Rmm Backdoors (report)
- proofpoint.com — Dont Trustconnect Its A Rat (report)