Skip to content
KitploitKITPLOIT
工具博客
提交
工具博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
awesome-rat — RAT与C&C资源。250+开源项目,1200+ RAT/C&C博客/视频。 | Kitploit
工具/GitHubGitHub/alphaseclab/awesome-rat
后渗透利用恶意软件分析渗透测试命令与控制论文与研究学习与教育红队精选资源远程访问工具
GitHubalphaseclab/awesome-rat

awesome-rat

RAT与C&C资源。250+开源项目,1200+ RAT/C&C博客/视频。

查看仓库
2.2k4776年前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

所有收集类项目

RAT

  • 250+ 开源远控/C&C工具,1200+ RAT分析报告\C&C相关文章等。
  • English Version

目录

  • 开源工具
    • pupy -> (1)工具 (6)文章
    • Covenant -> (3)工具 (18)文章
    • Slackor -> (1)工具 (3)文章
    • QuasarRAT -> (1)工具 (9)文章
    • EvilOSX -> (1)工具 (9)文章
    • Merlin -> (1)工具 (3)文章
  • 商业软件
    • Team Viewer -> (7)工具 (34)文章
  • 恶意软件(部分)
    • Gh0st -> (5)工具 (23)文章
    • NanoCore -> (1)工具 (32)文章
    • NjRat -> (4)工具 (20)文章
    • Revenge RAT -> (1)工具 (9)文章
    • PlugX -> (1)工具 (40)文章
    • (25) RemcosRAT
    • (3) L0rdixRAT
    • (1) LodaRAT
    • (9) GulfRAT
    • (14) NetWireRAT
    • (1) JhoneRAT
    • (2) Dacls
    • (1) BlackRemote
    • (17) Orcus
    • (1) NukeSped
    • (21) DarkComet
    • (1) WarZone RAT
    • (16) BlackShades
    • (1) DenesRAT
    • (4) WSH RAT
    • (2) Qrypter RAT
    • (20) Adwind
    • (1) CannibalRAT
    • (3) jRAT
    • (5) jsRAT
    • (4) CrossRat
    • (1) ArmaRat
    • (6) RokRAT
  • 利用公开服务
    • Telegram -> (3)工具 (2)文章
    • Twitter -> (2)工具 (6)文章
    • GMail -> (3)工具 (8)文章
    • Github -> (1)工具 (5)文章
    • DropBox -> (1)工具 (3)文章
    • 区块链 -> (2)工具 (1)文章
    • 其他 -> (15)工具 (5)文章
  • 通信协议
    • DNS协议
      • (9) 工具
      • (18) 文章
      • Domain Generation Algorithm(DGA) -> (14)工具 (42)文章
    • ICMP -> (5)文章
    • WebSocket -> (2)工具 (5)文章
  • C&C
    • Cobalt Strike -> (14)工具 (8)文章
    • 工具
      • (64) 新添加
    • 文章
      • (258) 新添加
  • 远控
    • 工具
      • (9) Android
      • (5) Linux
      • (17) Windows
      • (4) Apple
      • (90) 新添加
    • 文章

开源工具


pupy

工具

  • [5265星][1m] [Py] n1nj4sec/pupy Python编写的远控、后渗透工具,跨平台(Windows, Linux, OSX, Android)

文章

  • 2020.01 [TheCyberWire] PupyRAT is back. So is the Konni Group. Twitter storm over claims that MBS hacked Jeff Bezos....
  • 2019.03 [hackingarticles] Command & Control Tool: Pupy
  • 2017.11 [chokepoint] Pupy as a Metasploit Payload
  • 2017.10 [boredhackerblog] Pupy shell over Tor
  • 2017.02 [n0where] Open Source Cross Platform RAT: Pupy
  • 2015.10 [hackingarticles] Hack Remote PC using Pupy – Remote Administration Tool

Covenant

工具

  • [1147星][6d] [C#] cobbr/covenant Covenant is a collaborative .NET C2 framework for red teamers.
  • [95星][9d] [C#] cobbr/elite Elite is the client-side component of the Covenant project. Covenant is a .NET command and control framework that aims to highlight the attack surface of .NET, make the use of offensive .NET tradecraft easier, and serve as a collaborative command and control platform for red teamers.
  • [31星][4m] [C#] cobbr/c2bridge C2Bridges allow developers to create new custom communication protocols and quickly utilize them within Covenant.

文章

  • 2020.01 [csis] Embedding external DLLs into Covenant Tasks
  • 2020.01 [hakin9] Covenant the .NET based C2 on Kali Linux | by Dan Dieterle
  • 2019.12 [cyberarms] Covenant the .NET based C2 on Kali Linux
  • 2019.12 [rastamouse] Covenant Tasks 101
  • 2019.12 [rsa] Using RSA NetWitness to Detect C&C: Covenant
  • 2019.11 [4hou] Covenant利用分析
  • 2019.11 [3gstudent] Covenant利用分析
  • 2019.10 [cobbr] Covenant: Developing Custom C2 Communication Protocols
  • 2019.10 [specterops] Covenant: Developing Custom C2 Communication Protocols
  • 2019.09 [freebuf] Covenant:针对红队设计的.NET命令行控制框架
  • 2019.09 [stealthbits] Setup, Configuration, and Task Execution with Covenant: The Complete Guide
  • 2019.08 [stealthbits] Next-Gen Open Source C2 Frameworks in a Post PSEmpire World: Covenant
  • 2019.08 [rastamouse] Covenant, Donut, TikiTorch
  • 2019.08 [cobbr] Covenant: The Usability Update
  • 2019.08 [specterops] Covenant: The Usability Update
  • 2019.02 [cobbr] Entering a Covenant: .NET Command and Control
  • 2019.02 [rvrsh3ll]

Slackor

工具

  • [332星][12d] [Py] coalfire-research/slackor A Golang implant that uses Slack as a command and control server

文章

  • 2019.09 [freebuf] Slackor:Go语言写的一款C&C服务器
  • 2019.08 [freebuf] Slackor:如何将Slack当作你的命令控制服务器
  • 2019.06 [n00py] Introducing Slackor, a Remote Access Tool Using Slack as a C2 Channel

QuasarRAT

工具

  • [2932星][10m] [C#] quasar/quasarrat Remote Administration Tool for Windows

文章

  • 2019.10 [UltraHacks] QuasarRAT [Free Download] | [TUTORIAL VIDEO] | Ultra Hacks
  • 2018.09 [malwarebytes] Buggy implementation of CVE-2018-8373 vulnerability used to deliver Quasar RAT
  • 2018.03 [4hou] 深入分析利用宏代码传播NetwiredRC和Quasar RAT的恶意RTF文档
  • 2018.01 [paloaltonetworks] VERMIN: Quasar RAT and Custom Malware Used I
  • 2017.12 [HackerSploit] QuasarRAT - The Best Windows RAT? - Remote Administration Tool for Windows
  • 2017.11 [n0where] Free, Open-Source Remote Administration Tool for Windows: QuasarRAT
  • 2017.10 [TechnoHacker] Quasar RAT review
  • 2017.10 [rsa] MalSpam Delivers RAT SpyWare Quasar 9-27-2017
  • 2017.01 [paloaltonetworks] Downeks and Quasar RAT Used in Recent Targeted Attacks Against Go

EvilOSX

工具

  • [1376星][2y] [Py] marten4n6/evilosx An evil RAT (Remote Administration Tool) for macOS / OS X.

文章

  • 2019.07 [hackingarticles] EvilOSX-RAT for MacOS/OSX
  • 2019.06 [NullByte] Take Control Over MacOS Computers with EvilOSX [Tutorial]
  • 2018.08 [freebuf] EvilOSX:一款功能强大的macOS远程管理工具(RAT)
  • 2018.07 [pentesttoolz] EvilOSX – Evil Remote Administration Tool (RAT) for macOS/OS X – Kali Linux 2018.2
  • 2018.06 [n0where] Pure python post-exploitation RAT for macOS & OSX: EvilOSX
  • 2018.03 [applehelpwriter] defending against EvilOSX, a python RAT with a twist in its tail
  • 2018.03 [binarydefense] EvilOSX - Binary Defense
  • 2018.03 [binarydefense] EvilOSX
  • 2017.11 [NullByte] EvilOSX RAT - How to build a payload and start a server

Merlin

工具

  • [2568星][6m] [Go] ne0nd0g/merlin Merlin is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in golang.

文章

  • 2019.03 [hackingarticles] Command and Control Guide to Merlin
  • 2018.02 [lockboxx] Merlin for Red Teams
  • 2017.12 [n0where] Cross-Platform Post-Exploitation HTTP/2 Command & Control Server: Merlin

商业软件


Team Viewer

工具

  • [405星][2y] [C++] vah13/extracttvpasswords tool to extract passwords from TeamViewer memory using Frida
  • [277星][2y] [C++] gellin/teamviewer_permissions_hook_v1 A proof of concept injectable C++ dll, that uses naked inline hooking and direct memory modification to change your TeamViewer permissions.
  • [175星][9d] uknowsec/sharpdecryptpwd 对密码已保存在 Windwos 系统上的部分程序进行解析,包括:Navicat,TeamViewer,FileZilla,WinSCP,Xmangager系列产品(Xshell,Xftp)。
  • [59星][2y] [Py] attackercan/teamviewer-dumper 从内存中转储TeamViewer ID 和密码
  • [42星][6d] [C#] v1v1/decryptteamviewer Enumerate and decrypt TeamViewer credentials from Windows registry
  • [36星][5y] [C++] kkar/teamviewer-dumper-in-cpp Dumps TeamViewer ID,Password and account settings from a running TeamViewer instance by enumerating child windows.
  • [25星][5m] [C++] dydtjr1128/remoteassistance-cpp [WIP]RemoteAssistance like TeamViewer(C++)

文章

  • 2020.02 [yoroi] Importante Vulnerabilità su TeamViewer
  • 2020.01 [freebuf] “正版”监控软件被黑产利用,输出把关不严或成另一个TeamViewer?
  • 2019.11 [sessionstack] TeamViewer, and Alternative Remote Access and Web Conferencing Solutions, Through the Lens of Customer Service
  • 2019.10 [threatbook] “TeamViewer被黑门”是确有其事还是夸大其词?别慌!一文看懂应对方法
  • 2019.10 [freebuf] TeamViewer据称“被入侵”事件的研判及结论
  • 2019.04 [4hou] 利用木马化TeamViewer针对多个国家政府机构的攻击行动
  • 2019.04 [0x00sec] Port 5900 open on a MAC that used Teamviewer, trying to access it
  • 2018.09 [blackmoreops] Install TeamViewer on Kali Linux 2018
  • 2018.08 [freebuf] 你下载的TeamViewer13破解版可能有毒
  • 2018.08 [4hou] 使用RMS和TeamViewer攻击工业公司
  • 2018.08 [kaspersky] Attacks on industrial enterprises using RMS and TeamViewer
  • 2018.08 [securelist] Attacks on industrial enterprises using RMS and TeamViewer
  • 2017.12 [4hou] TeamViewer 13.0.5058中的权限漏洞测试
  • 2017.12 [3gstudent] TeamViewer 13.0.5058中的权限漏洞测试
  • 2017.12 [3gstudent] TeamViewer 13.0.5058中的权限漏洞测试

恶意软件(部分)


Gh0st

工具

  • [301星][7d] [C++] yuanyuanxiang/simpleremoter 基于gh0st的远程控制器:实现了终端管理、进程管理、窗口管理、远程桌面、文件管理、语音管理、视频管理、服务管理、注册表管理等功能
  • [273星][7y] [C++] sin5678/gh0st a open source remote administrator tool
  • [91星][6y] [C++] igh0st/gh0st3.6_src
  • [90星][1m] [C++] zibility/remote 参考Gh0st源码,实现的一款PC远程协助软件,拥有远程Shell、文件管理、桌面管理、消息发送等功能。
  • [21星][5m] [C++] holmesian/gh0st-light 精简之后的老东西

文章

  • 2020.01 [z3roTrust] Becoming Untraceable - 12.0_Gh0st_Us3r.dll
  • 2020.01 [rsa] Detecting Gh0st RAT in the RSA NetWitness Platform
  • 2019.06 [binarydefense] Gh0stCringe (Formerly CirenegRAT) - Binary Defense
  • 2019.03 [alienvault] The odd case of a Gh0stRAT variant
  • 2018.11 [trendmicro] 使用机器学习对Gh0st远控变种恶意网络数据流进行归类
  • 2018.08 [traffic] [2018-08-12] KaiXinEK->Gh0stRAT
  • 2018.07 [traffic] [2018-07-16] KaiXinEK->Gh0stRAT
  • 2018.07 [inquest] Field Notes: Malicious HFS Instances Serving Gh0stRAT
  • 2018.07 [360] 针对一个远控木马Gh0st RAT样本的初始化分析
  • 2018.05 [id] CryptGh0st
  • 2018.05 [freebuf] 解码Gh0st RAT变种中的网络数据
  • 2018.04 [freebuf] Gh0st大灰狼RAT家族通讯协议分析
  • 2018.04 [360] Gh0st/大灰狼RAT家族通讯协议分析
  • 2017.12 [traffic] [2017-12-06] KaiXinEK->Gh0stRAT
  • 2016.06 [cysinfo] Hunting and Decrypting Communications of Gh0st RAT in Memory
  • 2014.05 [pediy] [原创]Gh0st3.6 windows7无法连接bug分析
  • 2014.04 [pediy] [讨论]Gh0st3.6 IOCP发送BUG

NanoCore

工具

  • [2星][10m] [Py] jacobpimental/nanocore_extractor Extracts nanocore sample from compile AutoIT script

文章

  • 2020.01 [molly] NanoCore: The RAT that keeps on keeping on. How to detect and prove an infection.
  • 2019.11 [4hou] 双加载的ZIP文件传播Nanocore RAT
  • 2019.10 [morphisec] NanoCore RAT Under the Microscope
  • 2019.06 [myonlinesecurity] More AgentTesla keylogger and Nanocore RAT in one bundle
  • 2019.06 [myonlinesecurity] Nanocore RAT via fake DHL failed delivery in Chinese
  • 2019.06 [4hou] 解析NanoCore犯罪软件攻击链
  • 2019.06 [yoroi] Dissecting NanoCore Crimeware Attack Chain
  • 2019.05 [myonlinesecurity] nanocore RAT via fake order in password protected word doc with wrong password
  • 2019.05 [myonlinesecurity] Fake Fedex Express Shipment For Pickup in iso delivers nanocore using Sendgrid
  • 2019.05 [goggleheadedhacker] Unpacking NanoCore Sample Using AutoIT
  • 2019.03 [carbonblack] TAU Threat Intelligence Notification: NanoCore – Old Malware, New Tricks!
  • 2019.01 [myonlinesecurity] Fake Autec Power purchase Order delivers Nanocore RAT
  • 2019.01 [myonlinesecurity] Nanocore via fake order using dde in csv files
  • 2019.01 [myonlinesecurity] Nanocore RAT via fake order emails

NjRat

工具

  • [143星][2y] [Visual Basic .NET] alibawazeeer/rat-njrat-0.7d-modded-source-code NJR
  • [128星][8d] [Visual Basic] mwsrc/njrat njRAT SRC Extract
  • [14星][5m] [C#] nyan-x-cat/njrat-0.7d-stub-csharp njRAT C# Stub - Fixed For PowerShell
  • [3星][2y] [Py] seep1959/njutils A client and chat program for njrat 0.6.4, 0.7d, and 0.7d golden edition.

文章

  • 2019.12 [carbonblack] Threat Analysis Unit (TAU) Threat Intelligence Notification: njRAT
  • 2019.09 [freebuf] Gorgon APT组织再做文章:DropBox到NJRat的曲折历程
  • 2019.05 [morphisec] A look at Hworm / Houdini AKA njRAT
  • 2019.05 [myonlinesecurity] Fake Payment receipt vbs drops njrat bladabindi downloads Agent Tesla via Sendspace.
  • 2018.11 [trendmicro] 由AutoIt编译的蠕虫, 利用可移动介质传播, 投递无文件版的njRAT远控
  • 2018.06 [360] 老树开新花--njRAT家族恶意软件分析报告
  • 2018.06 [freebuf] 技术讨论 | NjRAT通过base64编码加密混淆Code免杀绕过360杀毒实验
  • 2018.04 [UltraHacks] njRAT v0.7 | Tutorial | www.ultrahacks.org | Ultra Hacks
  • 2018.03 [broadanalysis] Guest Blog Post: njRat Analysis with Volatility
  • 2018.01 [rsa] Malspam delivers njRAT 1-11-2018
  • 2017.12 [malwarenailed] Revisiting HWorm and NjRAT
  • 2016.12 [freebuf] 史上最全的njRAT通信协议分析
  • 2016.08 [MalwareAnalysisForHedgehogs] Malware Analysis - Unpacking njRAT Protected by Confuser v.1.9 and others
  • 2016.01 [sensecy] Is There A New njRAT Out There?
  • 2015.12 [sec] 木马情报分析之:njRAT&H-worm

Revenge RAT

工具

  • [21星][2m] [C#] nyan-x-cat/revengerat-stub-cssharp Revenge-RAT C# Stub - Fixed

文章

  • 2020.01 [malware] 2020-01-15 - QUICK POST: MALSPAM PUSHING REVENGE RAT
  • 2019.11 [fortinet] Double Trouble: RevengeRAT and WSHRAT
  • 2019.09 [360] Revenge-RAT is used in phishing emails attacks against Italy
  • 2019.04 [4hou] 利用钓鱼邮件传播RevengeRAT的Aggah行动
  • 2019.03 [alienvault] Mapping TrickBot and RevengeRAT with MITRE ATT&CK and AlienVault USM Anywhere
  • 2019.02 [4hou] Revenge RAT恶意软件升级版来袭
  • 2018.04 [dissectmalware] Stealthy VBScript dropper dropping Revenge RAT
  • 2017.10 [rsa] Malspam Delivers Revenge RAT October-2017
  • 2016.08 [deniable] Lurking Around Revenge-RAT

PlugX

工具

  • [28星][7y] [Py] kcreyts/plugxdecoder Decodes PlugX traffic and encrypted/compressed artifacts

文章

  • 2020.01 [hexacorn] The Wizard of X – Oppa PlugX style, Part 2
  • 2019.11 [BorjaMerino] Rebind Socket Windows: PoC PlugX Controller
  • 2018.06 [countuponsecurity] Digital Forensics – PlugX and Artifacts left behind
  • 2018.05 [countuponsecurity] Malware Analysis – PlugX – Part 2
  • 2018.02 [4hou] 揭秘PlugX 恶意软件家族的攻击实力
  • 2018.02 [360] PlugX恶意软件分析报告
  • 2018.02 [countuponsecurity] Malware Analysis – PlugX
  • 2017.09 [fortinet] Deep Analysis of New Poison Ivy/PlugX Variant - Part II
  • 2017.09 [fortinet] 新型 Poison Ivy/PlugX 变种深入分析
  • 2017.09 [360] Stack overflow in PlugX RAT
  • 2017.07 [hexacorn] The Wizard of X – Oppa PlugX style
  • 2017.02 [jpcert] PlugX + Poison Ivy = PlugIvy? - PlugX Integrating Poison Ivy’s Code -
  • 2016.06 [airbuscybersecurity] Getting a PlugX builder
  • 2016.06 [cylance] CylancePROTECT® vs. PlugX – JTB Breach Affects 7.93 Million People in Japan
  • 2016.03 [securelist] PlugX malware: A good hacker is an apologetic hacker
  • 2015.11 [volatility] PlugX: Memory Forensics Lifecycle with Volatility

RemcosRAT

  • 2019.10 [fortinet] New Variant of Remcos RAT Observed In the Wild
  • 2019.09 [myonlinesecurity] Some changes to Remcos Rat persistence method
  • 2019.09 [myonlinesecurity] Fake invoice tries to deliver Remcos RAT
  • 2019.09 [freebuf] 钓鱼邮件中的Remcos RAT变种分析
  • 2019.08 [trendmicro] Analysis: New Remcos RAT Arrives Via Phishing Email
  • 2019.06 [myonlinesecurity] Remcos Rat via fake invoice using multiple delivery methods.
  • 2019.06 [HackerSploit] Remcos RAT Review - The Most Advanced Remote Access Tool
  • 2018.11 [myonlinesecurity] More Fake DHL invoices delivering Remcos RAT via office XML files
  • 2018.10 [myonlinesecurity] Fake DHL READ : (DHL Express) -Delivery Address Confirmation delivers Remcos Rat
  • 2018.09 [myonlinesecurity] Fake Purchase Order email delivers Remcos RAT
  • 2018.09 [360] 揭秘Remcos下的僵尸网络
  • 2018.08 [securityledger] Cisco Links Remote Access Tool Remcos to Cybercriminal Underground
  • 2018.08 [talosintelligence] Picking Apart Remcos Botnet-In-A-Box
  • 2018.08 [UltraHacks] Remcos RAT Tutorial | Remote Administration Tool | Ultra Hacks

L0rdixRAT

  • 2019.08 [bromium] Decrypting L0rdix RAT’s C2
  • 2019.07 [bromium] An Analysis of L0rdix RAT, Panel and Builder
  • 2018.11 [ensilo] L0RDIX: Multipurpose Attack Tool

LodaRAT

  • 2020.02 [talosintelligence] Loda RAT Grows Up

GulfRAT

  • 2020.01 [TheCyberWire] Phishing with a RAT in the Gulf. More on how Jeff Bezos was hacked. Microsoft discloses data...
  • 2020.01 [TheCyberWire] Escalation in the Gulf as a US air strike kills Iran’s Quds commander. Travelex and RavnAir...
  • 2019.08 [nettitude] Tanker Cyber Attacks taking place in the Gulf
  • 2017.09 [mikefrobbins] PowerShell Toolmaking session this Saturday, September 30th at Gulf Coast Code Camp 2017 in Mobile, Alabama
  • 2016.11 [fireeye] FireEye Responds to Wave of Destructive Cyber Attacks in Gulf Region
  • 2016.03 [elearnsecurity] Visit eLearnSecurity on Gulf Information Security and Gulf Expo 2016 in Dubai
  • 2015.07 [welivesecurity] New report explains gulf between security experts and non-experts
  • 2010.08 [publicintelligence] Los Zetas and Gulf Cartel Perpetrators of Mexican Drug Trafficking Violence Organizational Chart
  • 2010.05 [publicintelligence] BP Minerals Management Service Workshop Brief: Unlocking Gulf of Mexico “Technological Challenges”

NetWireRAT

  • 2020.01 [securityintelligence] New NetWire RAT Campaigns Use IMG Attachments to Deliver Malware Targeting Enterprise Users
  • 2019.11 [carbonblack] Active C2 Discovery Using Protocol Emulation Part1 (HYDSEVEN NetWire)
  • 2019.09 [fortinet] New NetWire RAT Variant Being Spread Via Phishing
  • 2019.08 [malware] 2019-08-23 - DATA DUMP (URSNIF, RIG EK, NETWIRE RAT)
  • 2019.04 [myonlinesecurity] Fake DHL Shipment Notification delivers Netwire Trojan
  • 2018.11 [traffic] [2018-11-21] HookAds->FalloutEK->AZORult->NetWireRAT
  • 2017.11 [myonlinesecurity] Fake HSBC Advising Service Payment Advice malspam delivers Netwire trojan
  • 2017.10 [myonlinesecurity] Fake HSBC Swift Copy delivers Netwire trojan
  • 2017.09 [TechnoHacker] NetWire HKCU/Run vs ActiveX Startup
  • 2017.08 [TechnoHacker] Netwire Tutorial: How to Sign the Android Host
  • 2017.04 [TechnoHacker] How to crypt Netwire with Cyberseal
  • 2017.04 [TechnoHacker] Netwire RAT Review
  • 2014.08 [paloaltonetworks] NetWire and MITRE
  • 2014.08 [paloaltonetworks] New Release: Decrypting NetWire C

JhoneRAT

  • 2020.01 [talosintelligence] JhoneRAT: Cloud based python RAT targeting Middle Eastern countries

Dacls

  • 2019.12 [360] Lazarus Group使用Dacls RAT攻击Linux平台
  • 2019.12 [360] Dacls, the Dual platform RAT

BlackRemote

  • 2019.12 [carbonblack] Threat Analysis Unit (TAU) Threat Intelligence Notification: BlackRemote RAT

Orcus

  • 2019.11 [krebsonsecurity] Orcus RAT Author Charged in Malware Scheme
  • 2019.01 [morphisec] New Campaign Delivers Orcus RAT
  • 2018.04 [freebuf] 基于SYLK文件传播Orcus远控木马样本分析
  • 2017.12 [fortinet] Circle of the fraud: more information about Bitcoin Orcus RAT campaign
  • 2017.12 [fortinet] Circle of the fraud: more information about Bitcoin Orcus RAT campaign
  • 2017.12 [fortinet] A Peculiar Case of Orcus RAT Targeting Bitcoin Investors
  • 2017.12 [fortinet] Orcus 远控瞄准比特币投资者, 伪装成比特币交易机器人 Gunbot 进行传播
  • 2017.05 [freebuf] Orcus VM的解题步骤
  • 2017.04 [hackingarticles] Hack the Orcus VM CTF Challenge
  • 2017.04 [techanarchy] VulnHub Orcus Solution
  • 2017.03 [vulnhub] hackfest2016: Orcus
  • 2017.03 [vulnhub] hackfest2016: Orcus
  • 2016.08 [deniable] Cracking Orcus RAT
  • 2016.08 [deniable] Cracking Orcus RAT
  • 2016.08 [deniable] Cracking Orcus RAT
  • 2016.08 [paloaltonetworks] Orcus – Birth of an unusual plugin bu

NukeSped

  • 2019.10 [fortinet] A Deep-Dive Analysis of the NukeSped RATs

DarkComet

  • 2018.09 [UltraHacks] How to setup DarkCometRAT 5.3.1 + Portforward
  • 2018.04 [freebuf] CVE-2017-11882新动态:利用AutoIT脚本释放DarkComet后门
  • 2018.03 [tencent] CVE-2017-11882新动态:利用AutoIT脚本释放DarkComet后门
  • 2017.10 [rsa] Malspam Delivers DarkComet RAT October-2017
  • 2017.01 [HackingMonks] Darkcomet Rat Tutorial (Trojans are awesome)
  • 2016.02 [hackingarticles] Hack Remote PC using Darkcomet RAT with Metasploit
  • 2015.11 [TechnoHacker] How to setup DarkComet RAT [Voice Tutorial] [Download Link]
  • 2015.07 [SecurityBSidesLondon] Kevin Breen - DarkComet From Defense To Offense - Identify your Attacker
  • 2015.03 [heimdalsecurity] Security Alert: Infamous DarkComet RAT Used In Spear Phishing Campaigns
  • 2015.03 [sketchymoose] Smooshing the Square Peg into the Round Hole: DarkComet Plugin for 64-bit images
  • 2012.07 [freebuf] DarkComet RAT作者宣布项目停止开发
  • 2012.06 [freebuf] [更新]一款强大的远控 – DarkComet RAT V5.3.1
  • 2012.06 [malwarebytes] You dirty RAT! Part 1: DarkComet
  • 2012.04 [trendmicro] Fake Skype Encryption Software Cloaks DarkComet Trojan
  • 2012.04 [toolswatch] DarkComet-RAT Remote Administration Tool v5.1.1 released

WarZone RAT

  • 2018.11 [UltraHacks] Warzone RAT C++ | Hidden VNC [PROMOTION VIDEO]| Ultra Hacks

BlackShades

  • 2017.01 [TechnoHacker] Blackshades Revisited
  • 2016.02 [TechnoHacker] How to use Blackshades [download link]
  • 2016.02 [TechnoHacker] How to setup Blackshades RAT [Voice Tutorial] [download link]
  • 2014.05 [malwarebytes] Taking off the Blackshades
  • 2014.05 [endgame] Blackshades: Why We Should Care About Old Malware
  • 2014.05 [trendmicro] The Blackshades RAT – Entry-Level Cybercrime
  • 2014.05 [publicintelligence] FBI Blackshades Remote Access Tool Private Sector Bulletins and Domain List
  • 2014.05 [alienvault] Blackshades Smackdown & Poking China in the Eye
  • 2014.05 [cylance] A Study in Bots: BlackShades Net
  • 2014.05 [welivesecurity] Behind Blackshades: a closer look at the latest FBI cyber crime arrests
  • 2014.05 [krebsonsecurity] ‘Blackshades’ Trojan Users Had It Coming
  • 2014.05 [malwaretech] FBI Cybercrime Crackdown – Blackshades
  • 2012.07 [malwarebytes] BlackShades Co-Creator Arrested!
  • 2012.06 [malwarebytes] BlackShades in Syria
  • 2012.06 [citizenlab] Syrian Activists Targeted with BlackShades Spy Software

DenesRAT

  • 2019.10 [nsfocus] 海莲花(APT32)组织 DenesRAT木马与相关攻击链分析

WSH RAT

  • 2019.10 [angelalonso] WSH RAT - Analysis of the code
  • 2019.10 [angelalonso] Fudcrypt using H-Worm from WSH RAT
  • 2019.09 [freebuf] 黑客购买新型WSH RAT最新变种样本,攻击银行客户
  • 2019.09 [angelalonso] WSH RAT and the link to unknowcrypter and Fudcrypt

Qrypter RAT

  • 2018.04 [4hou] 对愈加流行的Qrypter RAT运作情况进行分析
  • 2017.12 [angelalonso] Qrypter Java RAT using Tor

Adwind

  • 2019.08 [4hou] Adwind远控当前被广泛用于公共事业部门的攻击活动中
  • 2018.10 [reversinglabs] eWeek: Cisco Talos and ReversingLabs warn that the Adwind Remote Access Trojan (RAT) has added capabilities that enable it bypass some anti-virus technologies
  • 2018.04 [4hou] 垃圾邮件活动使用XTRAT、DUNIHI和Adwind后门
  • 2018.04 [trendmicro] 趋势科技研究人员监控到垃圾邮件传播跨平台远控Adwind, 同时捆绑了后门XTRAT和DUNIHI和Loki
  • 2018.04 [ensilo] enSilo Blocks New Variant of Adwind RAT
  • 2018.03 [OALabs] Analyzing Adwind / JRAT Java Malware
  • 2018.03 [heimdalsecurity] Security Alert: Spam Campaign Spreads Adwind RAT variant, Targeting Computer Systems
  • 2018.02 [fortinet] New jRAT/Adwind Variant Being Spread With Package Delivery Scam
  • 2018.02 [rsa] Winds of Winter - MalSpam Delivers Adwind RAT 2-1-2018
  • 2018.02 [myonlinesecurity] Fake Swift Copy malspam via compromised sites delivering Java Adwind/ QRAT /JRAT Trojan
  • 2017.12 [myonlinesecurity] Fake “Your UPS Invoice Is Ready” malspam delivers Java Adwind / Java JRAT Trojan
  • 2017.08 [netskope] Adwind RAT employs new obfuscation techniques
  • 2017.07 [trendmicro] Spam Campaign Delivers Cross-platform Remote Access Trojan Adwind

CannibalRAT

  • 2018.02 [talosintelligence] CannibalRAT targets Brazil

jRAT

  • 2018.10 [cofense] H-Worm and jRAT Malware: Two RATs are Better than One
  • 2018.08 [Sebdraven] Lammers, stealers and RATs: same technics like Formbook malware to install JRAT and HawkEye…
  • 2018.03 [trustwave] Crypter-as-a-Service Helps jRAT Fly Under The Radar

jsRAT

  • 2018.02 [netskope] ShortJSRAT leverages cloud with scriptlets
  • 2017.07 [rsa] Recreating the Crime Scene - A JSRat Story
  • 2016.05 [evi1cg] JSRAT几种启动方式
  • 2016.03 [hackingarticles] Hack Remote Windows 10 PC using JSRAT
  • 2015.07 [secist] 使用JSRAT远程管理win10系统

CrossRat

  • 2018.01 [360] 分析一款全球网络间谍活动中的跨平台恶意软件-CrossRAT(下)
  • 2018.01 [4hou] CrossRat远程控制软件的分析
  • 2018.01 [360] 分析一款全球网络间谍活动中的跨平台恶意软件-CrossRAT(上)
  • 2018.01 [objective] 分析用于全球网络间谍活动的跨平台远控 CrossRAT

ArmaRat

  • 2018.09 [360] ArmaRat:针对伊朗用户长达两年的间谍活动

RokRAT

  • 2018.01 [morphisec] Threat Profile: RokRAT
  • 2017.12 [MalwareAnalysisForHedgehogs] Malware Analysis - ROKRAT Unpacking from Injected Shellcode
  • 2017.11 [talosintelligence] ROKRAT Reloaded
  • 2017.06 [alienvault] A RAT that Tweets: New ROKRAT Malware Hides behind Twitter, Amazon, and Hulu Traffic
  • 2017.04 [360] 使用云平台的ROKRAT木马分析
  • 2017.04 [talosintelligence] ROKRAT 远控分析:从钓鱼到payload,以Twitter/Yandex/Mediafire做C&C。

CatKARAT

  • 2018.01 [hackingarticles] TCP & UDP Packet Crafting with CatKARAT

TheFatRat

  • 2018.11 [freebuf] 技术分享 | 看我如何使用TheFatRat黑掉你的Android手机
  • 2017.11 [TheHackerStuff] TheFatRat - Hacking Over WAN - Embedding Payload in Original Android APK - Without Port Forwarding
  • 2016.12 [TheHackerStuff] Kali Linux - TheFatRat - Creating an Undetectable Backdoor - Bypass all AntiVirus
  • 2016.09 [freebuf] TheFatRat:Msfvenom傻瓜化后门生成工具
  • 2016.07 [hackingarticles] Hack Remote Windows 10 PC using TheFatRat

OmniRAT

  • 2017.07 [skycure] Nasty backdoor OmniRAT is back, disguised as GhostCtrl on Android mobile devices
  • 2015.11 [freebuf] OmniRAT变种木马被恶意利用

LuminosityLink

  • 2018.10 [welivesecurity] LuminosityLink RAT pack leader jailed 30 months in the US
  • 2018.02 [paloaltonetworks] RAT Trapped? LuminosityLink Falls Foul of Vermin Eradicatio
  • 2017.05 [UltraHacks] How to setup LuminosityLink RAT with nVPN | PORTFORWARD FIX!!!
  • 2017.05 [umbrella] The Weather Report: Seamless Campaign, LuminosityLink RAT, and OG-Miner!
  • 2017.03 [myonlinesecurity] Request for 1st new order proforma invoice malspam delivers LuminosityLink RAT
  • 2016.07 [paloaltonetworks] Investigating the LuminosityLink Remote Access Trojan Conf

其他

  • 2020.02 [proofpoint] Proofpoint Q4 2019 Threat Report and Year in Review — The Year of the RAT Ends with More of the Same
  • 2020.01 [sentinelone] CISO Essentials | How Remote Access Trojans Affect the Enterprise
  • 2020.01 [TheCyberWire] RATs, backdoors, and a remote code execution zero-day. Hoods breach Mitsubishi Electric. Telnet...
  • 2020.01 [freebuf] 针对在有效数字证书内植入远控木马病毒分析报告
  • 2020.01 [rambus] Cable Haunt vulnerability can give hackers remote access to approximately 200 million cable modems
  • 2020.01 [proofpoint] Threat Insight 2019 in Review: Year of the RAT
  • 2019.12 [ptsecurity] Turkish tricks with worms, RATs… and a freelancer
  • 2019.12 [infosecinstitute] Malware spotlight: What is a Remote Access Trojan (RAT)?
  • 2019.12 [UltraHacks] Dark Shades Android RAT | Ultra Hacks
  • 2019.11 [broadanalysis] Fallout Exploit Kit delivers suspect Remote Access Trojan (RAT)
  • 2019.11 [carbonblack] Threat Analysis Unit (TAU) Threat Intelligence Notification: AsyncRAT
  • 2019.11 [proofpoint] Proofpoint Q3 2019 Threat Report — Emotet’s return, RATs reign supreme, and more
  • 2019.10 [tencent] 快Go矿工(KuaiGoMiner)控制数万电脑挖矿,释放远控木马窃取机密

Read more

下载工具
(1) CatKARAT
  • (5) TheFatRat
  • (2) OmniRAT
  • (6) LuminosityLink
  • (477) 其他
  • Entering a Covenant: .NET Command and Control
  • 2019.01 [specterops] Entering a Covenant: .NET Command and Control
  • 2017.12 [malwarebytes] Use TeamViewer? Fix this dangerous permissions bug with an update
  • 2017.11 [360] 基于TeamViewer的瞄准小公司的远控木马分析
  • 2017.08 [freebuf] 利用Frida从TeamViewer内存中提取密码
  • 2017.04 [4hou] 深入了解恶意软件如何滥用TeamViewer?
  • 2017.02 [4hou] TeamSpy又回来了,TeamViewer变成了它的攻击载体
  • 2016.12 [trendmicro] New SmsSecurity Variant Roots Phones, Abuses Accessibility Features and TeamViewer
  • 2016.10 [broadanalysis] Rig Exploit Kit via EITEST delivers malicious payload and TeamViewer Remote Control
  • 2016.06 [trendmicro] Unsupported TeamViewer Versions Exploited For Backdoors, Keylogging
  • 2016.06 [] 运用最广的远控-TeamViewer被黑了
  • 2016.06 [radware] Has TeamViewer Been Hacked?
  • 2016.06 [fortinet] Threat Landscape Perspectives: TeamViewer Attack – Spy vs. Spy Misdirection?
  • 2016.03 [privacy] Surprise, Hackers Use TeamViewer to Spread Ransomware
  • 2015.08 [volatility] Recovering TeamViewer (and other) Credentials from RAM with EditBox
  • 2015.06 [] 获取运行中的TeamViewer的账号和密码
  • 2014.05 [trendmicro] Remote Help for Family and Friends – Part 1: Installing and Using TeamViewer
  • 2014.02 [webroot] Managed TeamViewer based anti-forensics capable virtual machines offered as a service
  • 2014.01 [robert] Howto install Teamviewer 9.x on Ubuntu >= 12.04 64bit (in my case 13.10)
  • 2013.05 [security] Installing Teamviewer 8 on Kali 64bit (Debian)
  • 2013.03 [securelist] The TeamSpy Crew Attacks – Abusing TeamViewer for Cyberespionage
  • 2014.03 [trendmicro] Kunming Attack Leads to Gh0st RAT Variant
  • 2013.08 [pediy] 二次的gh0st
  • 2013.06 [trendmicro] Targeted Attack in Taiwan Uses Infamous Gh0st RAT
  • 2012.11 [trendmicro] DaRK DDoSseR Leads to Gh0st RAT
  • 2012.06 [alienvault] New MaControl variant targeting Uyghur users, the Windows version using Gh0st RAT
  • 2012.05 [forcepoint] The Amnesty International UK website was compromised to serve Gh0st RAT [Update]
  • 2019.01 [malware] 2019-01-04 - MALSPAM PUSHES NANOCORE RAT
  • 2018.11 [myonlinesecurity] Fake Payment Receipt delivers Nanocore RAT malware
  • 2018.06 [UltraHacks] NanoCore [Free Download] [No Virus] [DL] | Ultra Hacks
  • 2018.04 [myonlinesecurity] Fake PAYMENT CONFIRMATION emails deliver Nanocore RAT
  • 2018.04 [myonlinesecurity] Nanocore Rat delivered via fake order emails
  • 2018.04 [myonlinesecurity] Nanocore via fake Purchase order malspam using Microsoft Office Equation Editor exploits
  • 2018.04 [myonlinesecurity] Nanocore RAT delivered by fake order malspam
  • 2018.02 [krebsonsecurity] Bot Roundup: Avalanche, Kronos, NanoCore
  • 2017.11 [myonlinesecurity] Fake Product Enquiry malspam delivers Nanocore RAT
  • 2017.10 [fortinet] PDF Phishing Leads to Nanocore RAT, Targets French Nationals
  • 2017.10 [fortinet] 内置 JavaScript 脚本的PDF 恶意文件,启动时通过 Google Drive 分享链接下载 HTA 文件,由 HTA 文件下载并执行 NanoCore 远控
  • 2017.08 [myonlinesecurity] Angelika Rodriguez – [email protected] – Purchase Order malspam delivers nanocore RAT
  • 2017.05 [netskope] NanocoreRAT delivery via cloud storage apps shifts from .uue to .r11
  • 2017.03 [itsjack] Nanocore Cracked Alcatraz – Leaving The Door Open
  • 2016.10 [sans] Malspam delivers NanoCore RAT
  • 2016.02 [paloaltonetworks] NanoCoreRAT Behind an Increase in Tax-Themed Phishin
  • 2015.11 [f] Halloween RAT: NanoCore Served Via PageFair Service
  • 2015.04 [ensilo] NanoCore RAT: It’s Not 100% Original
  • 2015.11 [alienvault] KilerRat: Taking over where Njrat remote access trojan left off
  • 2015.08 [virusbulletin] Paper: Life after the apocalypse for the Middle Eastern NJRat campaign
  • 2014.08 [mcafee] Trailing the Trojan njRAT
  • 2014.08 [mcafee] Trailing the Trojan njRAT
  • 2014.01 [rsa] Detecting njRAT in Your Environment
  • 2015.09 [cyintanalysis] Using threat_note To Track Campaigns: Returning to PIVY and PlugX Infrastructure
  • 2015.09 [airbuscybersecurity] Volatility plugin for PlugX updated
  • 2015.08 [rebsnippets] PlugX Chronicles
  • 2015.08 [cyintanalysis] Threat Analysis: Poison Ivy and Links to an Extended PlugX Campaign
  • 2015.08 [airbuscybersecurity] Latest changes in PlugX
  • 2015.05 [paloaltonetworks] PlugX Uses Legitimate Samsung Application for DLL Sid
  • 2015.04 [freebuf] 恶意代码分析:台湾官方版英雄联盟LoL和流亡黯道PoE被植入远控工具PlugX
  • 2015.01 [jpcert] Analysis of a Recent PlugX Variant - “P2P PlugX”
  • 2015.01 [] A Closer Look at PlugX from League of Legends / Path of Exile
  • 2015.01 [trendmicro] PlugX Malware Found in Official Releases of League of Legends, Path of Exile
  • 2014.06 [trendmicro] PlugX RAT With “Time Bomb” Abuses Dropbox for Command-and-Control Settings
  • 2014.06 [lastline] An Analysis of PlugX Using Process Dumps from High-Resolution Malware Analysis
  • 2014.01 [airbuscybersecurity] PlugX "v2": meet "SController"
  • 2014.01 [airbuscybersecurity] PlugX: some uncovered points
  • 2013.12 [lastline] An Analysis of PlugX Malware
  • 2013.05 [freebuf] FireEye:PlugX老马新用,针对中国政治活动的APT攻击分析
  • 2013.04 [trendmicro] New Wave of PlugX Targets Legitimate Apps
  • 2013.04 [securelist] Winnti returns with PlugX
  • 2012.09 [freebuf] 国外大牛人肉定向攻击远控PlugX开发者全过程分析
  • 2012.09 [alienvault] The connection between the Plugx Chinese gang and the latest Internet Explorer Zeroday
  • 2012.09 [trendmicro] Unplugging PlugX Capabilities
  • 2012.09 [alienvault] Tracking down the author of the PlugX RAT
  • 2012.09 [freebuf] 新型远程控制工具Plugx正在被利用并通过钓鱼攻击日本政府
  • 2012.09 [trendmicro] PlugX: New Tool For a Not So New Campaign
  • 2018.07 [myonlinesecurity] Fake DHL “Alert! Shipment Notification” delivers Remcos RAT
  • 2018.05 [fortinet] Remcos远控变种利用CVE-2017-11882传播
  • 2018.04 [myonlinesecurity] Remcos RAT delivered by fake ” your workers are fighting” message
  • 2018.04 [myonlinesecurity] Remcos RAT delivered via fake CCICM international debt recovery service
  • 2018.04 [myonlinesecurity] Fake Payment recovery email spoofing CCICM international debt recovery service delivers Remcos rat via Microsoft Equation Editor Exploits
  • 2018.03 [tencent] 新型远控木马Remcos利用CVE-2017-11882漏洞进行实时攻击
  • 2018.03 [myonlinesecurity] Fake order spoofed from Finchers ltd Sankyo-Rubber delivers Remcos RAT via ACE attachments
  • 2017.09 [malwarebreakdown] Malvertising Leads to RIG EK and Drops Remcos RAT.
  • 2017.09 [trendmicro] 云平台 Autodesk® A360 被利用传播 Adwind, Remcos, Netwire RAT 等恶意软件
  • 2017.08 [cybereason] Cybereason creates 'vaccine' to stop Remcos RAT
  • 2017.02 [fortinet] REMCOS: A New RAT In The Wild
  • 2016.07 [krebsonsecurity] Canadian Man Behind Popular ‘Orcus RAT’
  • 2012.03 [quequero] DarkComet Analysis – Understanding the Trojan used in Syrian Uprising
  • 2012.02 [trendmicro] DarkComet Surfaced in the Targeted Attacks in Syrian Conflict
  • 2011.08 [toolswatch] DarkComet-RAT (Remote Administration Tool) v4.0 Fix 1 available
  • 2011.05 [toolswatch] DarkComet-RAT v3.3 available
  • 2011.01 [toolswatch] (EXCLUSIVE) DarkComet-RAT updated to v3.0.1
  • 2011.01 [toolswatch] EXCLUSIVE : DarkComet-RAT 3.0 released (Impressive RAT tool)
  • 2012.06 [malwarebytes] You Dirty RAT! Part 2 – BlackShades NET
  • 2017.03 [freebuf] Adwind RAT针对企业攻击,目标超过100个国家和地区
  • 2017.01 [codemetrix] Decrypting Adwind jRAT jBifrost trojan
  • 2016.08 [fortinet] JBifrost: Yet Another Incarnation of the Adwind RAT
  • 2016.07 [heimdalsecurity] Security Alert: Adwind RAT Used in Targeted Attacks with Zero AV Detection
  • 2016.02 [securelist] Expert: cross-platform Adwind RAT
  • 2016.02 [kaspersky] The wind that smells like RAT: The story of Adwind MaaS
  • 2013.11 [crowdstrike] Adwind RAT Rebranding
  • 2019.10 [4hou] 快go矿工(KuaiGoMiner)控制数万电脑挖矿,释放远控木马窃取机密
  • 2019.10 [proofpoint] TA505 Distributes New SDBbot Remote Access Trojan with Get2 Downloader
  • 2019.10 [tencent] “月光(Moonlight)”蠕虫威胁高校网络,中毒电脑被远程控制
  • 2019.10 [4hou] “月光(Moonlight)”蠕虫威胁高校网络,中毒电脑被远程控制
  • 2019.10 [freebuf] 反间谍之旅:首款安卓远控木马工具分析
  • 2019.09 [4hou] 病毒团伙利用phpStudy RCE漏洞批量抓鸡,下发四个远控木马
  • 2019.09 [aliyun] 利用badusb对用户进行木马远控
  • 2019.09 [sensecy] ARABIC-SPEAKING THREAT ACTOR RECYCLES THE SOURCE CODE OF POPULAR RAT SPYNOTE AND SELLS IT IN THE DARK WEB, AS NEW
  • 2019.08 [securelist] Fully equipped Spying Android RAT from Brazil: BRATA
  • 2019.08 [talosintelligence] RAT Ratatouille: Backdooring PCs with leaked RATs
  • 2019.08 [malware] 2019-08-26 - DATA DUMP: SOCGHOLISH CAMPAIGN PUSHES NETSUPPORT RAT
  • 2019.08 [fortinet] Fake Indian Income Tax Calculator Delivers xRAT Variant
  • 2019.07 [tencent] 商贸信家族新活跃:利用钓鱼邮件传播商业远控木马RevetRAT
  • 2019.07 [freebuf] 关于远控木马你应该了解的知识点
  • 2019.07 [trendmicro] Spam Campaign Targets Colombian Entities with Custom-made ‘Proyecto RAT,’ Uses Email Service YOPmail for C&C
  • 2019.07 [freebuf] APT34核心组件Glimpse:远控复现与流量分析
  • 2019.07 [d] Red Team Diary, Entry #1: Making NSA’s PeddleCheap RAT Invisible
  • 2019.07 [yoroi] Spotting RATs: Tales from a Criminal Attack
  • 2019.07 [cybersecpolitics] Book Review: Delusions of Intelligence, R.A. RATCLIFF
  • 2019.07 [4hou] 探寻木马进化趋势:APT32多版本远控木马Ratsnif的横向分析
  • 2019.07 [4hou] 浅谈远控木马
  • 2019.07 [freebuf] 投递恶意lnk使用JwsclTerminalServer实现远程控制和信息获取
  • 2019.07 [securityintelligence] Taking Over the Overlay: What Triggers the AVLay Remote Access Trojan (RAT)?
  • 2019.07 [securityintelligence] Taking Over the Overlay: Reverse Engineering a Brazilian Remote Access Trojan (RAT)
  • 2019.07 [talosintelligence] RATs and stealers rush through “Heaven’s Gate” with new loader
  • 2019.06 [4hou] 警惕H-worm蠕虫病毒伪装电影样片钓鱼,草率点击附件会中远控木马
  • 2019.06 [nightst0rm] Tôi đã chiếm quyền điều khiển của rất nhiều trang web như thế nào?
  • 2019.06 [4hou] TA505在最新攻击活动中使用HTML, RAT和其他技术
  • 2019.06 [trendmicro] Shifting Tactics: Breaking Down TA505 Group’s Use of HTML, RATs and Other Techniques in Latest Campaigns
  • 2019.05 [4hou] 提高恶意软件多任务处理能力的Babylon RAT
  • 2019.05 [360] 记一次利用XLM宏投放远控工具的垃圾邮件活动
  • 2019.05 [arxiv] [1905.07273] Finding Rats in Cats: Detecting Stealthy Attacks using Group Anomaly Detection
  • 2019.05 [freebuf] 基于Python的BS远控Ares实战
  • 2019.05 [4hou] C&C远控工具:WebSocket C2
  • 2019.04 [paloaltonetworks] BabyShark Malware Part Two – Attacks Continue Using KimJongRAT
  • 2019.04 [freebuf] 看我如何揪出远控背后的幕后黑手
  • 2019.04 [4hou] C&C远控工具:Ares
  • 2019.04 [krebsonsecurity] Who’s Behind the RevCode WebMonitor RAT?
  • 2019.04 [freebuf] 门罗币挖矿&远控木马样本分析
  • 2019.04 [4hou] 门罗币挖矿+远控木马样本分析
  • 2019.04 [4hou] LimeRAT在野外传播
  • 2019.04 [yoroi] LimeRAT spreads in the wild
  • 2019.04 [alexander] Week 6 Cyberattack Digest 2019 – ExileRAT trojan, Eskom Group, and others
  • 2019.03 [360] 木马作者主动提交Tatoo远控后门程序
  • 2019.03 [flashpoint] FIN7 Revisited: Inside Astra Panel and SQLRat Malware
  • 2019.03 [tencent] 挖矿木马针对SQL服务器爆破攻击 中招可致服务器被远程控制
  • 2019.03 [paloaltonetworks] Cardinal RAT Sins Again, Targets Israeli Fin-T
  • 2019.03 [aliyun] 分析如何使用JAVA-VBS来传播RAT
  • 2019.03 [malware] 2019-03-06 - QUICK POST: KOREAN MALSPAM PUSHES FLAWED AMMYY RAT MALWARE
  • 2019.03 [4hou] JAVA+VBS传播RAT
  • 2019.03 [mcafee] JAVA-VBS Joint Exercise Delivers RAT
  • 2019.02 [dodgethissecurity] Reverse Engineering an Unknown RAT – Lets call it SkidRAT 1.0
  • 2019.02 [4hou] ExileRAT与LuckyCat共享C2基础设施
  • 2019.02 [freebuf] 小米M365电动滑板车面临黑客攻击和远程控制风险
  • 2019.02 [myonlinesecurity] Fake Blockchain authentication update delivers Dark Comet RAT
  • 2019.02 [securityartwork] Case study: “Imminent RATs” (III)
  • 2019.02 [securityartwork] Case study: “Imminent RATs” (II)
  • 2019.02 [securityledger] ExileRAT Malware Targets Tibetan Exile Government
  • 2019.02 [securityartwork] Case study: “Imminent RATs” (I)
  • 2019.02 [talosintelligence] ExileRAT shares C2 with LuckyCat, targets Tibet
  • 2019.02 [0x00sec] Programming language for Remote Access Toolkit
  • 2019.01 [angelalonso] Fudcrypt: the service to crypt Java RAT through VBS scripts and Houdini malware
  • 2019.01 [yoroi] The Story of Manuel’s Java RAT
  • 2019.01 [0x00sec] RATs question. Long break
  • 2019.01 [aliyun] 使用AMP技术分析RAT威胁
  • 2019.01 [360] 利用Marvell Avastar Wi-Fi中的漏洞远程控制设备:从零知识入门到RCE漏洞挖掘利用(下)
  • 2019.01 [aliyun] 使用MS Word文档传播.Net RAT恶意软件
  • 2019.01 [tencent] 腾讯电脑管家:“大灰狼”远控木马伪装成“会所会员资料”传播
  • 2019.01 [360] 利用Marvell Avastar Wi-Fi中的漏洞远程控制设备:从零知识入门到RCE漏洞挖掘利用(上)
  • 2019.01 [4hou] 使用MS Word文档传播.Net RAT恶意软件
  • 2019.01 [0x00sec] VPS or a VPN for a RAT?
  • 2019.01 [talosintelligence] What we learned by unpacking a recent wave of Imminent RAT infections using AMP
  • 2019.01 [fortinet] .Net RAT Malware Being Spread by MS Word Documents
  • 2019.01 [4hou] TA505将新的ServHelper Backdoor和FlawedGrace RAT添加到其军火库中
  • 2019.01 [tencent] 劫持浏览器、远程控制、视频刷量,这种破解激活工具有毒!
  • 2019.01 [4hou] 广告恶意软件伪装成游戏、远程控制APP感染900万Google play用户
  • 2019.01 [UltraHacks] Ozone RAT C++ | Hidden VNC [TUTORIAL VIDEO] | Ultra Hacks
  • 2019.01 [micropoor] 高级持续渗透-第八季demo便是远控
  • 2019.01 [tencent] 疑似Gorgon组织使用Azorult远控木马针对中国外贸行业的定向攻击活动
  • 2019.01 [4hou] JungleSec勒索软件通过IPMI远程控制台感染受害者
  • 2019.01 [sans] Remote Access Tools: The Hidden Threats Inside Your Network
  • 2018.12 [freebuf] tRat:一种出现在多起垃圾电子邮件活动中的新型模块化RAT
  • 2018.12 [k7computing] Scumbag Combo: Agent Tesla and XpertRAT
  • 2018.12 [360] Flash 0day + Hacking Team远控:利用最新Flash 0day漏洞的攻击活动与关联分析
  • 2018.12 [freebuf] Flash 0day+Hacking Team远控:利用最新Flash 0day漏洞的攻击活动与关联分析
  • 2018.11 [4hou] tRat:新模块化RAT
  • 2018.11 [proofpoint] tRat: 多个垃圾邮件行动中传播的新型模块化远控
  • 2018.11 [checkpoint] October 2018’s Most Wanted Malware: For The First Time, Remote Access Trojan Reaches Top 10 Threats | Check Point Software Blog
  • 2018.11 [checkpoint] October 2018’s Most Wanted Malware: For The First Time, Remote Access Trojan Reaches Global Threat Index’s Top 10
  • 2018.10 [DEFCONConference] DEF CON 26 CAR HACKING VILLAGE - Dan Regalado - Meet Salinas, 1st SMS commanded Car Infotainment RAT
  • 2018.10 [cybrary] “I smell a rat!” – AhMyth, not a Myth
  • 2018.10 [4hou] 如何在工业领域中使用RAT进行攻击
  • 2018.10 [360] 远控木马盗用网易官方签名
  • 2018.10 [ncsc] RATs, Mimikatz and other domestic pests
  • 2018.10 [infosecinstitute] Interview with RaT, the High Council President of SOLDIERX
  • 2018.10 [vulnerability0lab] Facebook Inc via Instagram Business - Remote Access Token Vulnerability (Original Facebook Video)
  • 2018.10 [securityledger] Episode 114: Complexity at Root of Facebook Breach and LoJax is a RAT You Can’t Kill
  • 2018.10 [sophos] IP EXPO Europe 2018: Sophos experts talk AI, privacy vs security, and RATs
  • 2018.09 [kaspersky] Threats posed by using RATs in ICS
  • 2018.09 [kaspersky] Industrial networks in need of RAT control
  • 2018.09 [securelist] Threats posed by using RATs in ICS
  • 2018.08 [traffic] [2018-08-22] Unknown->RigEK->AZORult->BabylonRAT
  • 2018.08 [freebuf] Hero RAT:一种基于Telegram的Android恶意软件
  • 2018.08 [4hou] 垃圾邮件活动滥用SettingContent-ms传播FlawedAmmyy RAT
  • 2018.08 [aliyun] 基于Telegram的安卓恶意软件HeroRAT分析
  • 2018.08 [alienvault] Off-the-shelf RATs Targeting Pakistan
  • 2018.07 [k7computing] Weaponized.IQY: A Quest to Deliver the FlawedAmmyy RAT
  • 2018.07 [trendmicro] Spam Campaign Abusing SettingContent-ms Found Dropping Same FlawedAmmy RAT Distributed by Necurs
  • 2018.07 [k7computing] Weaponized.IQY: A Quest to Deliver the FlawedAmmyy RAT
  • 2018.07 [4hou] 高度复杂的寄生虫RAT已出现在暗网
  • 2018.07 [proofpoint] Parasite HTTP RAT cooks up a stew of stealthy tricks
  • 2018.07 [aliyun] Vermin RAThole深度分析
  • 2018.07 [proofpoint] TA505 Abusing SettingContent-ms within PDF files to Distribute FlawedAmmyy RAT
  • 2018.07 [welivesecurity] Vermin one of three RATs used to spy on Ukrainian government institutions
  • 2018.07 [freebuf] HeroRAT:一款全新的基于Telegram的安卓远程访问木马
  • 2018.06 [heimdalsecurity] Security Alert: New Spam Campaign Delivers Flawed Ammyy RAT to Infect Victims’ Computers
  • 2018.06 [welivesecurity] HeroRAT: 基于Telegram的Android远控, 使用Xamarin框架编写
  • 2018.06 [4hou] 美国政府最新技术警报:警惕朝鲜黑客组织Hidden Cobra正在使用的两款RAT和蠕虫病毒
  • 2018.06 [4hou] NavRAT利用美朝元首脑会晤作为对韩国袭击的诱饵
  • 2018.06 [360] NavRAT借美朝会晤话题攻击韩国
  • 2018.05 [talosintelligence] NavRAT Uses US-North Korea Summit As Decoy For Attacks In South Korea
  • 2018.05 [myonlinesecurity] Necurs delivering Flawed Ammy RAT via IQY Excel Web Query files
  • 2018.05 [freebuf] 被黑的Drupal网站被用来挖矿,传播远控,发送诈骗邮件
  • 2018.05 [andreafortuna] Malware VM detection techniques evolving: an analysis of GravityRAT
  • 2018.05 [360] GravityRAT:以印度为APT目标两年内的演变史
  • 2018.05 [pcsxcetrasupport3] A closer look at “NetSupport”(Rat) top 2 layers
  • 2018.05 [freebuf] 神话传奇:一款通过卖号在微信群传播的远控木马
  • 2018.04 [virusbulletin] GravityRAT malware takes your system's temperature
  • 2018.04 [360] 神话传奇——通过卖号微信群传播的远控木马
  • 2018.04 [talosintelligence] GravityRAT - The Two-Year Evolution Of An APT Targeting India
  • 2018.04 [UltraHacks] WebMonitor RAT - NO PORTFORWARD NEEDED + FREE VPN NEW
  • 2018.04 [4hou] 吃鸡辅助远控木马分析
  • 2018.04 [freebuf] 吃鸡辅助远控木马分析
  • 2018.04 [360] 吃鸡辅助远控木马分析
  • 2018.04 [4hou] 利用Digital Ocean构建远控基础设施
  • 2018.04 [flashpoint] RAT Gone Rogue: Meet ARS VBS Loader
  • 2018.04 [lookout] mAPT ViperRAT Found in Google Play
  • 2018.04 [bitdefender] RadRAT: An all-in-one toolkit for complex espionage ops
  • 2018.04 [paloaltonetworks] Say “Cheese”: WebMonitor RAT Comes with C2-as-a-Servic
  • 2018.04 [freebuf] DELPHI黑客编程(三):简单远控原理实现
  • 2018.04 [fireeye] Fake Software Update Abuses NetSupport Remote Access Tool
  • 2018.04 [freebuf] PowerShell-RAT:一款基于Python的后门程序
  • 2018.03 [UltraHacks] Spynote v5.8 Android RAT | Tutorial | www.ultrahacks.org | Ultra Hacks
  • 2018.03 [360] TeleRAT:再次发现利用Telegram来定位伊朗用户的Android恶意软件
  • 2018.03 [paloaltonetworks] TeleRAT: Another Android Trojan Leveraging Telegram’s Bot API to Target Iran
  • 2018.03 [4hou] 三星SmartCam相机被曝存在十多个安全漏洞,可被远程控制、修改视频画面
  • 2018.03 [360] 针对OS X上Coldroot RAT跨平台后门的详细分析
  • 2018.03 [freebuf] 前端黑魔法之远程控制地址栏
  • 2018.03 [broadanalysis] EiTest campaign Hoefler Text Pop-up delivers NetSupport Manager RAT
  • 2018.03 [leavesongs] 前端黑魔法之远程控制地址栏
  • 2018.03 [broadanalysis] Fake Flash update leads to NetSupport RAT
  • 2018.03 [broadanalysis] EiTest campaign Hoefler Text Pop-up delivers NetSupport Manager RAT
  • 2018.03 [4hou] 高清无码!比鬼片还刺激!且听“诡娃”远控的这首惊魂曲
  • 2018.03 [freebuf] 高清无码!比鬼片还刺激!且听“诡娃”远控的这首惊魂曲
  • 2018.03 [360] 胆小者慎入!比鬼片还刺激!且听“诡娃”远控的这首惊魂曲
  • 2018.02 [broadanalysis] Fake Flash update leads to NetSupport RAT
  • 2018.02 [broadanalysis] EiTest campaign Hoefler Text Pop-up delivers NetSupport Manager RAT
  • 2018.02 [myonlinesecurity] Fake DHL notification delivers some sort of Java RAT
  • 2018.02 [4hou] 新的AndroRAT变种正在利用过期的Root漏洞伺机发起攻击
  • 2018.02 [objective] Tearing Apart the Undetected (OSX)Coldroot RAT
  • 2018.02 [trendmicro] New AndroRAT Exploits Dated Privilege Escalation Vulnerability, Allows Permanent Rooting
  • 2018.02 [360] 远控木马巧设“白加黑”陷阱:瞄准网店批发商牟取钱财
  • 2018.01 [broadanalysis] EiTest campaign Hoefler Text Pop-up delivers NetSupport Manager RAT
  • 2018.01 [4hou] 暴雪游戏存在严重远程控制漏洞,数亿用户受影响
  • 2018.01 [riskiq] Espionage Campaign Leverages Spear Phishing, RATs Against Turkish Defense Contractors
  • 2018.01 [freebuf] NDAY漏洞CVE-2017-11882与0Day漏洞CVE-2018-0802漏洞组合传播远控木马的样本分析
  • 2018.01 [broadanalysis] EiTest campaign Hoefler Text Pop-up delivers NetSupport Manager RAT
  • 2018.01 [netskope] Git Your RATs Here!
  • 2018.01 [redcanary] We Smell a RAT: Detecting a Remote Access Trojan That Snuck Past a User
  • 2018.01 [rsa] Malspam delivers BITTER RAT 01-07-2018
  • 2018.01 [freebuf] 移动端C#病毒“东山再起”,利用知名应用通信实现远控隐私窃取
  • 2017.12 [tencent] 通过CHM文件传播的Torchwood远控木马分析
  • 2017.12 [avlsec] 移动端C#病毒“东山再起”,利用知名应用通信实现远控隐私窃取
  • 2017.12 [broadanalysis] Fake Flash Player update delivers Net Support RAT
  • 2017.12 [netskope] TelegramRAT evades traditional defenses via the cloud
  • 2017.12 [4hou] Palo Alto Networks最新发现:UBoatRAT远程木马访问程序入侵东亚
  • 2017.12 [TechnoHacker] RATs in a Nutshell
  • 2017.11 [paloaltonetworks] UBoatRAT Navigates
  • 2017.11 [buguroo] New banking malware in Brazil - XPCTRA RAT ANALYSIS
  • 2017.11 [traffic] [2017-11-18] KaiXinEK->RAT
  • 2017.11 [freebuf] 通过CHM文件传播的Torchwood远控木马分析
  • 2017.11 [qq] 通过CHM文件传播的Torchwood远控木马分析
  • 2017.11 [TechnicalMujeeb] A-RAt exploit Tool Remote Access Android using Termux App.
  • 2017.11 [securityintelligence] 使用 AutoIt 脚本绕过 AV 检测的远控分析
  • 2017.11 [360] Powershell Empire 绕过AV实现远控
  • 2017.10 [riskiq] New htpRAT Gives Complete Remote Control Capabilities to Chinese Threat Actors
  • 2017.10 [lookout] JadeRAT mobile surveillanceware spikes in espionage activity
  • 2017.10 [buguroo] RAT Protection for Banking Customers That Works
  • 2017.10 [cylance] Cylance vs. Hacker’s Door Remote Access Trojan
  • 2017.10 [malwarebytes] 一个“正常的”Word 文档启动时自动下载恶意的 RTF 文件(利用 CVE-2017-8759),再由此 RTF 文件下载执行最终的 Payload
  • 2017.10 [rsa] Malspam Delivers HWorm RAT October, 2017
  • 2017.09 [freebuf] 【评论更新“木马”作者回复】“大黄蜂”远控挖矿木马分析与溯源
  • 2017.09 [intezer] Agent.BTZ/ComRAT 变种分析
  • 2017.09 [360] 分析利用“永恒之蓝”漏洞传播的RAT
  • 2017.09 [UltraHacks] SilentBytes RAT 1.6.3c | Multi Administration Tool!
  • 2017.09 [freebuf] 螳螂捕蝉黄雀在后,免费散播Cobian远控工具背后的秘密
  • 2017.09 [360] 如何远程控制别人的无线鼠标:深度揭露鼠标劫持内幕
  • 2017.09 [4hou] “钓鱼”插件实战:看我如何让粗心开发者的编辑器自动变身远控
  • 2017.09 [fortinet] 针对越南组织的 APT 攻击中使用的Rehashed 远控分析
  • 2017.09 [TechnoHacker] Arcom RAT: Is It Worth $3000?
  • 2017.08 [lookout] 安卓远控 xRAT
  • 2017.08 [paloaltonetworks] Updated KHRAT Malware Used in Cambodi
  • 2017.08 [JackkTutorials] How to make a HTTP RAT (#3)
  • 2017.08 [freebuf] 远控木马上演白利用偷天神技:揭秘假破解工具背后的盗刷暗流
  • 2017.08 [4hou] 远控木马上演白利用偷天神技:揭秘假破解工具背后的盗刷暗流
  • 2017.08 [fortinet] A Quick Look at a New KONNI RAT Variant
  • 2017.08 [freebuf] 如何把Photoshop改造成远程控制工具(RAT)来利用
  • 2017.08 [n0where] Koadic C3 COM Command & Control – JScript RAT
  • 2017.08 [cylance] Threat Spotlight: KONNI – A Stealthy Remote Access Trojan
  • 2017.08 [cylance] Cylance vs. KONNI RAT
  • 2017.08 [intezer] New Variants of Agent.BTZ/ComRAT Found: The Threat That Hit The Pentagon In 2008 Still Evolving; Part 1/2
  • 2017.08 [rsa] Malspam delivers Xtreme RAT 8-1-2017
  • 2017.07 [CodeColorist] How to turn Photoshop into a remote access tool
  • 2017.07 [pentestmag] Stitch – a Python written cross platform RAT
  • 2017.07 [freebuf] 【BlackHat 2017】小米9号平衡车国际版存在严重安全漏洞可被攻击者远程控制
  • 2017.07 [pentestingexperts] Hacking Android Smart Phone Using AhMyth Android RAT
  • 2017.07 [JackkTutorials] How to make a HTTP RAT (#2)
  • 2017.07 [ringzerolabs] Bladabindi RAT
  • 2017.07 [krebsonsecurity] Who is the GovRAT Author and Mirai Botmaster ‘Bestbuy’?
  • 2017.07 [JackkTutorials] How to make a HTTP RAT (#1)
  • 2017.06 [freebuf] 白利用的集大成者:新型远控木马上演移形换影大法
  • 2017.06 [pediy] [原创]一个远控木马的行为分析
  • 2017.06 [ColinHardy] JavaScript that drops a RAT - Reverse Engineer it like a pro
  • 2017.06 [4hou] 白利用的集大成者:新型远控木马上演移形换影大法
  • 2017.06 [360] 白利用的集大成者:新型远控木马上演移形换影大法
  • 2017.06 [freebuf] Metasploit实验:制作免杀payload+对任意“外网”主机的远控
  • 2017.06 [cylance] Cylance vs. FF-Rat Malware
  • 2017.06 [cylance] Threat Spotlight: Breaking Down FF-Rat Malware
  • 2017.06 [alienvault] Mac 平台首个 MaaS(恶意软件即服务)恶意软件 MacSpy 分析
  • 2017.05 [TechnoHacker] How to check if you're infected with a RAT in 10 seconds
  • 2017.05 [freebuf] 远控木马中的VIP:盗刷网购账户购买虚拟礼品卡
  • 2017.05 [pediy] [原创]从0分析一款经典的感染型远控木马
  • 2017.05 [4hou] 远控木马中的VIP:盗刷网购账户购买虚拟礼品卡
  • 2017.05 [sec] 远控木马中的VIP:盗刷网购账户购买虚拟礼品卡
  • 2017.05 [360] 远控木马中的VIP:盗刷网购账户购买虚拟礼品卡
  • 2017.05 [aliyun] FlexiSpy For Android远程控制后门
  • 2017.05 [UltraHacks] Imminent Monitor RAT setup & New update review 2017
  • 2017.05 [TechnoHacker] How to spread your RAT
  • 2017.05 [esecurityplanet] Shodan Partners with Recorded Future to Detect Botnets and RATs
  • 2017.04 [alienvault] The Felismus RAT: Powerful Threat, Mysterious Purpose
  • 2017.04 [4hou] 二十余款Linksys路由器曝出安全漏洞,或可被远程控制
  • 2017.04 [freebuf] 当心,安卓远控(spynote)升级了……
  • 2017.04 [paloaltonetworks] Cardinal RAT Active for Over
  • 2017.04 [jpcert] RedLeaves - Malware Based on Open Source RAT
  • 2017.03 [TechnoHacker] What's the difference between http botnets and RATs?
  • 2017.03 [paloaltonetworks] Trochilus and New MoonWind RATs Used In Attack Against Thai Orga
  • 2017.03 [fireeye] WMImplant – A WMI Based Agentless Post-Exploitation RAT Developed in PowerShell
  • 2017.03 [4hou] CIA事件余波:300多种思科交换机深受其毒,一个0day即可远程控制
  • 2017.03 [secist] 基于Python的远程管理工具(RAT) – Stitch
  • 2017.03 [trendmicro] MajikPOS简介:PoS恶意软件和RAT的结合体。
  • 2017.03 [4hou] Proton RAT利用0day漏洞升级新变种,最低1200美元可出售
  • 2017.02 [UltraHacks] SilentBytes RAT [beta] Windows 10 || PROMOTION ||
  • 2017.02 [UltraHacks] SilentBytes RAT Linux Ubuntu || PROMOTION ||
  • 2017.02 [UltraHacks] SilentBytes RAT 1.1 [BETA] Mac OS X || PROMOTION ||
  • 2017.02 [lookout] ViperRAT: The mobile APT targeting the Israeli Defense Force that should be on your radar
  • 2017.02 [talosintelligence] Go RAT, Go! AthenaGo points “TorWords” Portugal
  • 2017.02 [netskope] Decoys, RATs, and the Cloud: The growing trend
  • 2017.01 [malwarebytes] Mobile Menace Monday: AndroRAT Evolved
  • 2017.01 [malwarebytes] From a fake wallet to a Java RAT
  • 2016.12 [TechnoHacker] How to remotely execute a RAT on someone's PC
  • 2016.12 [cyber] The Kings In Your Castle Part 4 – Packers, Crypters and a Pack of RATs
  • 2016.11 [] Linux远控分析
  • 2016.11 [] Linux远控分析
  • 2016.11 [f] A RAT For The US Presidential Elections
  • 2016.11 [fidelissecurity] Down the H-W0rm Hole with Houdini's RAT
  • 2016.11 [4hou] 托管在Pastebin上的RAT木马会导致系统蓝屏
  • 2016.10 [malwarebytes] Get your RAT on Pastebin
  • 2016.10 [8090] 华为P9手机指纹锁遭破解,远程控制插座发微博,智能产品的安全问题堪忧
  • 2016.10 [sentinelone] GovRAT is Not New
  • 2016.10 [UltraHacks] [$25] Imment Monitor RAT setup
  • 2016.09 [securelist] TeamXRat: Brazilian cybercrime meets ransomware
  • 2016.09 [freebuf] 远控盗号木马伪装成850Game作恶
  • 2016.09 [jimwilbur] DroidJack – A Quick Look at an Android RAT
  • 2016.09 [360] 远控盗号木马伪装成850Game作恶
  • 2016.09 [countercept] Do you smell a rat?
  • 2016.09 [countercept] Do you smell a rat?
  • 2016.09 [freebuf] You dirty RAT:地下网络犯罪世界的“黑吃黑”
  • 2016.08 [fortinet] German Speakers Targeted by SPAM Leading to Ozone RAT
  • 2016.08 [freebuf] 微信曝远程任意代码执行漏洞,可被远程控制
  • 2016.08 [trustlook] Trustlook Discovers a Remote Administration Tool (RAT) Android Malware
  • 2016.08 [id] XRat, Team, Corporacao
  • 2016.08 [f] NanHaiShu: RATing the South China Sea
  • 2016.07 [malwarenailed] Luminosity RAT - Re-purposed
  • 2016.07 [360] 披合法外衣的远控木马——Game564深入分析
  • 2016.07 [fidelissecurity] Chasing Down RATs with Barncat
  • 2016.07 [n0where] Python Remote Access Tool: Ares
  • 2016.07 [360] H-WORM:简单而活跃的远控木马
  • 2016.06 [duo] Protecting Remote Access to Your Computer: RDP Attacks and Server Credentials for Sale
  • 2016.06 [cybereason] Permission to Execute: The Incident of the Signed and Verified RAT
  • 2016.06 [8090] 一款用于定向攻击的JavaScript远控木马分析
  • 2016.06 [hackingarticles] HTTP RAT Tutorial for Beginners
  • 2016.06 [avlsec] 假借知名应用植入恶意模块,披着羊皮的“狼”来了!WarThunder远程控制木马预警
  • 2016.06 [cysinfo] Hunting APT RAT 9002 In Memory Using Volatility Plugin
  • 2016.06 [f] Qarallax RAT: Spying On US Visa Applicants
  • 2016.06 [qq] 远控木马利用Windows系统文件漏洞展开攻击
  • 2016.06 [samvartaka] Dead RATs: Exploiting malware C2 servers
  • 2016.05 [freebuf] 深度:远控木马Posion Ivy开始肆虐缅甸和其它亚洲国家
  • 2016.05 [trendmicro] Lost Door RAT: Accessible, Customizable Attack Tool
  • 2016.04 [pentestpartners] RATing through the Steam Workshop
  • 2016.04 [freebuf] DameWare迷你远程遥控漏洞(CVE-2016-2345):让你玩转远程控制器
  • 2016.04 [paloaltonetworks] New Poison Ivy RAT Variant Targets Hong Kong Pro-Democracy
  • 2016.04 [sentinelone] Teaching an old RAT new tricks
  • 2016.04 [itsjack] RAT Threat Intelligence – A Very Simple Manual Technique
  • 2016.03 [TechnoHacker] How to port forward for any program and how to setup a DNS for RATs
  • 2016.03 [malwarebytes] Latest Steam Malware Shows Signs of RAT Activity
  • 2016.03 [freebuf] 如何远程控制别人的无线鼠标:深度揭露mouseJack内幕
  • 2016.03 [malwarebytes] This Steam Scam is a Rat Race
  • 2016.03 [itsjack] Imminent Monitor 4 RAT Analysis – Further Into The RAT
  • 2016.02 [TechnoHacker] How to get rid of a RAT [Very in depth]
  • 2016.02 [brindi] Advanced Techniques for Detecting RAT Screen Control
  • 2016.02 [mindedsecurity] RAT WARS 2.0: Advanced Techniques for Detecting RAT Screen Control
  • 2016.01 [fidelissecurity] Introducing Hi-Zor RAT
  • 2016.01 [alienvault] Trochilus RAT: Invading your Sandbox
  • 2016.01 [itsjack] Imminent Monitor 4 RAT Analysis – A Glance
  • 2016.01 [freebuf] “暗影大盗”远控木马分析报告
  • 2016.01 [] Linux远控分析
  • 2016.01 [ensilo] Cyber-Security in 120 Secs: 0-days, and a new RAT targeting APJ
  • 2016.01 [TechnoHacker] How to use all of Xtreme RAT's features
  • 2016.01 [freebuf] 一次对JSocket远控的分析
  • 2015.12 [paloaltonetworks] BBSRAT Attacks Targeting Russian Organizations Linked to Roam
  • 2015.12 [welivesecurity] Europol makes 12 arrests in Remote Access Trojan crackdown
  • 2015.11 [360] “大灰狼”远控木马幕后真凶深入挖掘
  • 2015.11 [cylance] Cylance vs. GlassRAT
  • 2015.11 [rsa] Detecting GlassRAT using Security Analytics and ECAT
  • 2015.11 [freebuf] KillerRat:埃及黑客开发针对Windows平台的新型RAT
  • 2015.11 [freebuf] BT天堂网站挂马事件后续:“大灰狼”远控木马分析及幕后真凶调查
  • 2015.11 [360] “大灰狼”远控木马分析及幕后真凶调查
  • 2015.11 [freebuf] 黑市热卖杀器GovRAT:恶意软件数字签名平台
  • 2015.11 [duo] Criminals Leverage Remote Access to Patient Data Applications
  • 2015.11 [fidelissecurity] A Stalker’s Best Friend: Inside JSocket’s Android Remote Access Tool Builder
  • 2015.10 [threatmetrix] How Contextual Fraud Prevention Can Turn Banks into RAT (Remote Access Trojan) Catchers
  • 2015.10 [deepsec] DeepSec Talk: Got RATs? Enter Barn Cat (OSint)
  • 2015.10 [360] 另类远控:木马借道商业级远控软件的隐藏运行实现
  • 2015.10 [freebuf] 另类远控:木马借道商业级远控软件的隐藏运行实现
  • 2015.10 [hackingarticles] Hack Android Devices using Omni RAT
  • 2015.10 [duo] Remote Access Trojan (RAT) Targets Windows Environments
  • 2015.09 [trustwave] Quaverse RAT: Remote-Access-as-a-Service
  • 2015.09 [freebuf] 远程控制工具VNC拒绝服务漏洞分析
  • 2015.09 [freebuf] 老式后门之美:五种复古远程控制工具(含下载)
  • 2015.09 [kaspersky] A layman’s dictionary: RAT
  • 2015.08 [sentinelone] The 7 ‘Most Common’ RATS In Use Today
  • 2015.08 [rsa] Detecting XtremeRAT variants using Security Analytics
  • 2015.08 [paloaltonetworks] RTF Exploit Installs Italian RAT:
  • 2015.08 [fortinet] The Curious Case Of The Document Exploiting An Unknown Vulnerability – Part 2: RATs, Hackers and Rihanna
  • 2015.08 [duo] You Built a Better Mousetrap? They Built Better RATs
  • 2015.08 [alienvault] FF-RAT Uses Stealth Tactics to Evade Endpoint Detection
  • 2015.08 [freebuf] 全程回放:黑客是如何远程控制切诺基汽车的?【FreeBuf视频】
  • 2015.08 [securityfuse] Omni RAT which can turn your android phone into a hacking machine
  • 2015.07 [redcanary] Red Canary vs. PoshRAT: Detection in the Absence of Malware
  • 2015.07 [freebuf] 格盘也没用:Hacking Team使用UEFI BIOS Rootkit将远控长驻操作系统
  • 2015.07 [freebuf] 揭秘:Hacking Team远控窃听程序(RCS)的全球热销之路
  • 2015.07 [] 简要分析Hacking Team远程控制系统
  • 2015.07 [freebuf] 简要分析Hacking Team远程控制系统
  • 2015.07 [bromium] Government Grade Malware: a Look at HackingTeam’s RAT
  • 2015.07 [nsfocus] 简要分析Hacking Team 远程控制系统
  • 2015.07 [talosintelligence] Ding! Your RAT has been delivered
  • 2015.06 [guidancesoftware] The OPM Hack: I Smell a RAT
  • 2015.05 [freebuf] 移花接木大法:新型“白利用”华晨远控木马分析
  • 2015.05 [securelist] Grabit and the RATs
  • 2015.05 [] 移花接木大法:新型“白利用”华晨远控木马分析
  • 2015.05 [] 移花接木大法:新型“白利用”华晨远控木马分析
  • 2015.04 [freebuf] 控制指令高达二十多种:远控木马Dendoroid.B分析报告
  • 2015.04 [freebuf] Adobe Flash播放器最新漏洞(CVE-2015-3044):摄像头和麦克风可被远程控制(含视频)
  • 2015.03 [freebuf] 剖析Smack技术远控木马
  • 2015.03 [avlsec] Smack技术远控木马
  • 2015.03 [] Smack技术远控木马工作分析文
  • 2015.02 [mcafee] What is a Remote Administration Tool (RAT)?
  • 2015.01 [] 移花接木大法:新型“白利用”华晨远控木马分析
  • 2015.01 [trendmicro] New RATs Emerge from Leaked Njw0rm Source Code
  • 2015.01 [freebuf] CVE-2014-8272漏洞分析:戴尔(Dell)远程控制卡脆弱的Session-ID机制
  • 2015.01 [] 远控木马Dendoroid.B分析报告
  • 2014.12 [sans] Flushing out the Crypto Rats - Finding "Bad Encryption" on your Network