Netskope Threat Labs

OctoRAT

ATP Sandbox Adv. Heuristics

OctoRAT is a remote access trojan that gives cyberattackers remote control of infected systems. The implant supports command execution, file theft, and payload downloads, and its campaigns typically arrive through phishing and loader chains. Responders should investigate the delivery path and hunt for persistence mechanisms after cleaning the implant.

First seen
December 2025
Last seen
October 2026
OctoRatOctorat
Alert Name
ByteCode-MSIL.Backdoor.OctoRat
ByteCode-MSIL.Trojan.OctoRat
Script-PowerShell.Trojan.OctoRat
Script-PowerShell.Trojan.OctoRAT
Script-WScript.Trojan.Octorat
Script-WScript.Trojan.OctoRat