Skip to main content
Mallory
MalwareUsed by 2 actorsExploits 3 CVEs

GobRAT

GobRAT is a Go-based Linux backdoor and router-focused RAT used to compromise edge devices and turn them into operational relay or anonymization infrastructure. Reporting describes it as a "swiss-army knife" backdoor with standard RAT functionality plus support for relaying attacks from compromised hosts, including DDoS activity, vulnerability exploitation campaigns, proxying/anonymization, reverse shell access, file operations, and system fingerprinting. It has been observed compiled for multiple architectures including x86-64, ARM, and MIPS, and primarily targets Linux routers and NAS devices, with Asus and Qnap specifically mentioned.

The malware has been documented by JPCERT/CC and later analyzed by Sekoia, which tracked infrastructure using GobRAT alongside the Bulbature implant to convert compromised edge devices into Operational Relay Boxes (ORBs). Sekoia assessed this infrastructure with high confidence to be operated by Chinese operators, citing code traces, language, and infrastructure usage. Separate reporting also notes weak infrastructure overlap between GobRAT-related infrastructure and activity clusters such as ViciousTrap, and states GobRAT anonymization nodes are assessed to be used by Chinese state-sponsored threat groups. Cisco Talos further noted that IPs hosting a Bulbature-related TLS certificate were associated with malware including GobRAT, SuperShell, and Cobalt Strike, all in China/Hong Kong-hosted infrastructure.

GobRAT is used to gather intelligence from networks associated with compromised edge devices while also providing attackers operational anonymity by launching attacks from victim systems instead of attacker-owned infrastructure. Sekoia reported a large ORB ecosystem involving GobRAT and Bulbature, with 63 servers identified, nearly 75,000 compromised hosts observed in July 2023 across 139 countries, and infections concentrated on edge devices globally, especially in the United States, Hong Kong, and Sweden. The operation used staging servers hosting Bash scripts and malware, persistence scripts, automated credential brute forcing, exploit campaigns against remote administration services, and web-based administration interfaces for managing compromised hosts, launching DDoS, brute-force, and exploitation campaigns, and creating on-demand proxy tunnels.

Detection content explicitly mentions YARA coverage for GobRAT, including a rule that identifies the backdoor by analyzing local addresses, MAC addresses, TCP communications, and telnet tasks. No standalone GobRAT hashes or domains are directly provided in the source content.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

EXPLOITED CVES

Vulnerabilities exploited

3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.

3 CVES
CVE-2017-5638Apache Struts Jakarta Multipart Parser Remote Code Execution

GobRAT, which has been already documented by the JP-CERT, is a swiss-army knife backdoor written in Go which has standard RAT functionalities and is also used to relay specific attacks from the compromised devices such as DDoS or vulnerability exploitation campaigns. It seems to be used to gather intelligence from the networks associated with the compromised edge devices.

via sekoia blogblog.sekoia.io
CVE-2019-13956Arbitrary PHP Code Execution via Language Cookie in Discuz!ML 3.2-3.4

GobRAT, which has been already documented by the JP-CERT, is a swiss-army knife backdoor written in Go which has standard RAT functionalities and is also used to relay specific attacks from the compromised devices such as DDoS or vulnerability exploitation campaigns. It seems to be used to gather intelligence from the networks associated with the compromised edge devices.

via sekoia blogblog.sekoia.io
CVE-2019-9082ThinkPHP Remote Command Execution via invokefunction

GobRAT, which has been already documented by the JP-CERT, is a swiss-army knife backdoor written in Go which has standard RAT functionalities and is also used to relay specific attacks from the compromised devices such as DDoS or vulnerability exploitation campaigns. It seems to be used to gather intelligence from the networks associated with the compromised edge devices.

via sekoia blogblog.sekoia.io
THREAT ACTORS

Groups observed using it

2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
ZIRCONIUM

GobRAT, which has been already documented by the JP-CERT, is a swiss-army knife backdoor written in Go which has standard RAT functionalities and is also used to relay specific attacks from the compromised devices such as DDoS or vulnerability exploitation campaigns. It seems to be used to gather intelligence from the networks associated with the compromised edge devices.

via sekoia blogblog.sekoia.io
Quad7

GobRAT, which has been already documented by the JP-CERT, is a swiss-army knife backdoor written in Go which has standard RAT functionalities and is also used to relay specific attacks from the compromised devices such as DDoS or vulnerability exploitation campaigns. It seems to be used to gather intelligence from the networks associated with the compromised edge devices.

via sekoia blogblog.sekoia.io
INDICATORS OF COMPROMISE

IOCs tracked for this family

12 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
9 tracked

IPs, domains, and DNS infrastructure linked to this family.

Hashes
1 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

Other
2 tracked

Other indicator types observed in public reporting.

TypeValueLatest sighting
domain●●●●●●●●●●●●View more in app2 years ago
domain●●●●●●●●●●●●View more in app2 years ago
domain●●●●●●●●●●●●View more in app2 years ago
domain●●●●●●●●●●●●View more in app2 years ago
domain●●●●●●●●●●●●View more in app2 years ago
domain●●●●●●●●●●●●View more in app2 years ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching12

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution2

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities3

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.