Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Malware ObliqueRAT

ObliqueRAT

TLP:CLEAR
Family

AI Analysis

· 2 days ago

Executive Summary

ObliqueRAT is a Windows Remote Access Trojan used by the Transparent Tribe for stealthy persistence and command execution. The malware mirrors capabilities seen in Crimson and has been operational since at least 2020, enabling attackers to exfiltrate data and extend lateral movement within targeted networks.

Enhanced Description

ObliqueRAT is a Windows‑based remote access trojan that has been actively leveraged by the cybercrime group Transparent Tribe since at least 2020. The malware functions as a backdoor, enabling attackers to remotely execute commands, transfer files, and potentially capture user input. Its architecture closely resembles that of Crimson, another well‑known RAT, suggesting shared development practices or tooling within the Transparent Tribe ecosystem. Because it is operated by a prolific threat actor, ObliqueRAT is considered part of an ongoing campaign aimed at gathering intelligence and facilitating further malicious activities. Threat intelligence feeds from Palo Alto Networks Talos report that ObliqueRAT has been observed in multiple campaigns dating to March 2021 and May 2021. Analysts note its use for stealthy persistence on compromised Windows hosts, allowing attackers to maintain long‑term access while obfuscating payload delivery through custom protocols and encrypted communications. Overall, the limited available data points to ObliqueRAT being a modular remote control tool capable of lateral movement, data exfiltration, and potentially additional post‑exploitation functionalities typical of advanced RAT families.

Key Capabilities

  • Remote command execution via custom C&C protocol
  • File upload and download between infected host and attacker
  • Screen capturing and keystroke logging (inferred from RAT behavior)
  • Persistence mechanisms on Windows platforms
  • Encrypted communications to avoid detection

ATT&CK Techniques

T1112
T1055
T1105
T1071.001
T1083

Recommended Actions

  • Identify and block outbound traffic to known ObliqueRAT C&C domains and IP addresses
  • Implement application whitelisting to prevent execution of unknown binaries
  • Monitor system logs for signs of remote desktop or PowerShell activity typical of RATs
  • Deploy endpoint detection and response solutions capable of detecting keystroke logging and screen capture behaviors
  • Apply timely security patches to reduce exploitation surface on Windows systems

Suggested Tags

Remote Access Trojan
RAT
Transparent Tribe
Windows Malware
Talos Intelligence
Crimson Similarity

Confidence Assessment

The information available is based solely on external threat intelligence references with limited technical detail. Confidence in the general description and attribution is moderate, but specific capabilities and operational parameters remain uncertain due to the absence of sample analysis or detailed malware behavior reports.

Description

ObliqueRAT is a remote access trojan, similar to Crimson, that has been in use by Transparent Tribe since at least 2020.(Citation: Talos Oblique RAT March 2021)(Citation: Talos Transparent Tribe May 2021)

Details

Type
Malware
Platforms
Windows
Confidence
90%
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.