Netskope Threat Labs

FatalRAT

ATP Sandbox Adv. HeuristicsNetskope IPS

FatalRAT is a remote access trojan that gives operators extensive control over infected Windows systems, including command execution, file transfer, and credential theft. Researchers have observed it in campaigns attributed to Chinese speaking actors, delivered through phishing and loader chains that target gaming, technology, and government victims. The family supports plugin modules, which lets its operators tailor stolen data collection to each intrusion.

First seen
November 2024
Last seen
September 2026
Alert Name
Win32.Trojan.FatalRAT
Win64.Trojan.FatalRAT