Skip to content

RAT

FatalRat

aka Sainbox RAT

FatalRAT is a most-likely chinese remote access tool distributed through forums and Telegram channels.

FatalRat, also known as Sainbox RAT, is a Windows rat.

Background

FatalRAT is a remote access tool of likely Chinese origin that spreads via forums and Telegram channels. Before completing infection, it runs a series of anti-virtual-machine checks to dodge detection. Once it gains a foothold, it decrypts its configuration strings, disables the CTRL+ALT+DELETE function, and starts a keylogger.

It can persist through registry changes or by creating a service, harvest sensitive information, and reach its command and control (C&C) server over encrypted channels. FatalRAT additionally spreads across networks by brute-forcing weak passwords.


Source: Malpedia (Fraunhofer FKIE).