Netskope Threat Labs

GodRAT

ATP Sandbox Adv. HeuristicsAV

GodRAT is a remote access trojan that shares a common origin with the AwesomePuppet RAT and shows code similarities with the two decade old Gh0st RAT code base. Researchers assess it is likely connected with Winnti threat actor activity, and its identification illustrates how threat actors rebuild and reuse legacy implant code against new victims.

First seen
September 2025
Last seen
October 2026
GodRatGodrat
Alert Name
Gen:Variant.GodRAT.2
Gen:Variant.GodRAT.9
Trojan.GodRAT.1
Win32.Backdoor.GodRat
Win32.Trojan.Godrat
Win32.Trojan.GodRat
Win32.Trojan.GodRAT