public mosaic llc support@publicmosaic.com
malware family

RatonRAT

8 addresses convicted as RatonRAT remote-access trojan controllers — 8 still listed, 0 archived. Observed from 2026-08-28.

TLP:CLEAR
addresses 8 8 still listed
observations 8 address and port pairs
networks 5 distinct ASNs
first seen 2026-08-28 oldest observation

Detection packs

Rules for the 8 still-listed addresses on this page, regenerated as the archive updates; archived episodes are omitted, and a rule can lag a withdrawal by up to five minutes. Suricata rules are rev:2 — alert tcp on address and port, alert tls where a full certificate fingerprint is published — and carry the archive's own episode ids as sids, so packs load beside each other and beside any per-host file. YARA packs are hash matches only: this site holds no file bytes.

About

A Windows commodity remote-access trojan, whose samples IOC aggregators have tracked as RatonRAT since February 2026 and whose listeners they have listed since March. In name and design it matches Raton Access Tool, or SillyRAT, an open-source C# RAT that vendor reporting describes being run as a paid service — a correspondence no vendor has stated outright. Do not confuse it with RatOn, the far more widely reported Android banking trojan that paired NFC-relay fraud with automated bank-app transfers in 2025: the two are unrelated programs run by different operators. The listeners recorded here presented self-signed certificates cut from one distinctive template, each on a different port — the shape of a product default deployed unchanged, and a shape the published Android-RatOn reporting nowhere describes.

Ports

:80802:14881:31321:48381:67671:70001:70701

Addresses

Ordered by when this archive first recorded them, newest first — a stable ordering, so a page holds the same addresses tomorrow. Archived addresses are included and marked; they are the majority of this corpus over time.