Netskope Threat Labs

ZgRAT

ATP Sandbox Adv. HeuristicsAV

ZgRAT is a .NET based remote access trojan and downloader that targets Windows systems through malicious Office documents and JavaScript payloads. Its implant maintains access, collects credentials and files, and downloads additional payloads for its operators, and researchers have observed it in campaigns that blend phishing with loader chains. Detections under this name warrant credential resets and a search for the delivery mechanism behind the implant.

First seen
October 2023
Last seen
October 2026
ZGRatZgrat
Alert Name
ByteCode-MSIL.Downloader.ZgRAT
ByteCode-MSIL.Trojan.ZgRAT
Document-Office.Trojan.Zgrat
GT:JS.ZGRat.1.06023AC9
GT:JS.ZGRat.1.1B4E4C24
GT:JS.ZGRat.1.1C607589
GT:JS.ZGRat.1.2C4C07E8
GT:JS.ZGRat.1.40ED8DED
GT:JS.ZGRat.1.43CA5425
GT:JS.ZGRat.1.43FAF18B