Skip to content

RAT

BreachRAT

This is a backdoor which FireEye call the Breach Remote Administration Tool (BreachRAT), written in C++.

BreachRAT is a Windows rat operated by Operation C-Major.

Background

This is a C++ backdoor that FireEye named the Breach Remote Administration Tool (BreachRAT). Its name comes from the hardcoded PDB path embedded in the RAT: C:\Work\Breach Remote Administration Tool\Release\Client.pdb


Source: Malpedia (Fraunhofer FKIE).