Mastodon Mastodon Mastodon Mastodon

Remote Access Trojan [RAT]

Updated: · CyberSecureFox Editorial Team

A remote access trojan (RAT) is malware that gives an attacker hidden, full remote control of an infected computer or phone.

How a RAT works

A RAT is disguised as something useful – an invoice, a game mod, a cracked program – so the victim installs it. After start it connects to the attacker’s command-and-control (C2) server and waits for commands. Typical functions include:

  • stealing passwords, browser cookies and crypto wallets;
  • keylogging and taking screenshots;
  • switching on the webcam and microphone;
  • uploading and downloading files, running commands, installing more malware.

Well-known families include njRAT, DarkComet, Remcos, AsyncRAT and Quasar; many are sold cheaply or are available as open source. On Android, banking RATs overlay fake screens and take over the device to make transfers.

Why RATs matter for security

RATs are a standard first step in many attacks: they give criminals a foothold inside a network from which they can move to servers and deploy ransomware. Espionage groups use custom RATs for long-term surveillance. Attackers also increasingly abuse legitimate remote management tools such as AnyDesk or ScreenConnect, which antivirus does not flag. RATs spread through phishing attachments, malicious ads, cracked software and fake updates.

How to protect yourself

  • Do not open unexpected attachments and do not run cracked or unofficial software.
  • Use endpoint protection with behavioural detection and keep the OS updated.
  • In companies, allow only approved remote access tools and monitor outgoing connections.
  • If a RAT is found, disconnect the device, change passwords from a clean device and reinstall the system.