Description
Farfli (a.k.a. Gh0st RAT, PCRat) is a remote access trojan associated with state sponsored and criminal actors that has evolved continuously since the late 2000s. It gives operators full control of infected Windows systems, including remote desktop viewing, file management, keystroke capture, and payload downloads. Thousands of variants have circulated because its source code leaked years ago, and its flexibility keeps it relevant in both targeted espionage and commodity intrusions.
Stats
- First seen
- February 2022
- Last seen
- October 2026
Alert name variants
| Alert Name |
|---|
| Backdoor.Farfli.AS |
| Backdoor.Farfli.AW |
| Binary.Backdoor.Farfli |
| ByteCode-MSIL.Backdoor.Farfli |
| Gen:Variant.Farfli.135 |
| Gen:Variant.Farfli.147 |
| Gen:Variant.Farfli.205 |
| Gen:Variant.Farfli.224 |
| Gen:Variant.Farfli.247 |
| Gen:Variant.Farfli.29 |

