Netskope Threat Labs

Farfli

ATP Sandbox Adv. HeuristicsAV

Farfli (a.k.a. Gh0st RAT, PCRat) is a remote access trojan associated with state sponsored and criminal actors that has evolved continuously since the late 2000s. It gives operators full control of infected Windows systems, including remote desktop viewing, file management, keystroke capture, and payload downloads. Thousands of variants have circulated because its source code leaked years ago, and its flexibility keeps it relevant in both targeted espionage and commodity intrusions.

First seen
February 2022
Last seen
October 2026
Alert Name
Backdoor.Farfli.AS
Backdoor.Farfli.AW
Binary.Backdoor.Farfli
ByteCode-MSIL.Backdoor.Farfli
Gen:Variant.Farfli.135
Gen:Variant.Farfli.147
Gen:Variant.Farfli.205
Gen:Variant.Farfli.224
Gen:Variant.Farfli.247
Gen:Variant.Farfli.29