A Remote Access Trojan (RAT) is a class of malware that provides an attacker covert, persistent, and unauthorized remote control over an infected system. Unlike legitimate remote administration tools, RATs operate without user consent, hide their presence, and are commonly used for:
Espionage & surveillance
Credential theft
Data exfiltration
Lateral movement
Long-term persistence (APT activity)
RATs often function as full-featured backdoors.
2. Typical RAT Architecture
2.1 Infection Chain (High-Level)
Initial Access
Phishing email (malicious attachment/link)
Drive-by download
Trojanized software / cracked tools
Supply chain compromise
Execution & Installation
Drops payload
Installs persistence
Establishes C2 communication
Command & Control (C2)
Attacker sends commands
RAT executes them and returns results
Post-Exploitation
Credential theft
Surveillance
Lateral movement
Data exfiltration
3. Core Capabilities of RATs
Capability
Description
Remote Shell
Execute OS commands
File Management
Upload/download/delete files
Credential Harvesting
Browser, system, VPN credentials
Keylogging
Capture keystrokes
Screen Capture
Screenshots or live desktop
Webcam/Mic Access
Audio/video spying
Process Control
Start/kill processes
Registry Manipulation
Persistence and evasion
Lateral Movement
SMB, RDP, WMI abuse
Self-Update
Download new modules
Defense Evasion
Disable AV, logging
4. Malicious Payload Types (Conceptual)
Note: Payload descriptions are categorical, not implementation guidance.