GobRAT is a Go-based Linux remote access trojan and backdoor used in campaigns that compromise internet-facing edge devices, especially routers and NAS systems. It has been observed in attacks against routers in Japan and in broader Operational Relay Box infrastructures that repurpose compromised edge devices as anonymization nodes, proxy relays, and attack platforms. Reporting has repeatedly associated GobRAT-related activity with China-nexus operations, including infrastructure overlaps with other malware used by Chinese-speaking or China-aligned threat actors.
GobRAT communicates with command-and-control servers over TLS and uses Go's gob serialization protocol for tasking and result exchange. Samples have been observed across multiple CPU architectures, including ARM, MIPS, x86, and x86-64, consistent with targeting heterogeneous embedded Linux environments. The malware has been distributed through shell-script-based infection chains that download the architecture-appropriate payload, establish persistence through scheduled restart mechanisms, disable local defenses such as firewalls, and install SSH-based backdoor access.
Its functionality extends beyond standard remote administration. Supported operations include host fingerprinting, reverse shell execution, file read and write operations, command-and-control reconfiguration, SOCKS5 proxying, and tunneling. GobRAT has also been documented attempting authentication against services such as SSH, Telnet, Redis, MySQL, and PostgreSQL on other systems, as well as scanning HTTP and HTTPS services and conducting dictionary attacks. Some observed command sets support distributed denial-of-service activity using multiple protocols. These capabilities make GobRAT suitable both for espionage support and for turning compromised devices into relay infrastructure for follow-on intrusion activity.
GobRAT employs basic protection and concealment measures, including packed binaries and encrypted embedded strings. It has been described as a multi-purpose backdoor used to gather intelligence from networks associated with compromised edge devices while also enabling operators to launch attacks from victim infrastructure rather than their own.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
GobRAT, which has been already documented by the JP-CERT, is a swiss-army knife backdoor written in Go which has standard RAT functionalities and is also used to relay specific attacks from the compromised devices such as DDoS or vulnerability exploitation campaigns. It seems to be used to gather intelligence from the networks associated with the compromised edge devices.
GobRAT, which has been already documented by the JP-CERT, is a swiss-army knife backdoor written in Go which has standard RAT functionalities and is also used to relay specific attacks from the compromised devices such as DDoS or vulnerability exploitation campaigns. It seems to be used to gather intelligence from the networks associated with the compromised edge devices.
GobRAT, which has been already documented by the JP-CERT, is a swiss-army knife backdoor written in Go which has standard RAT functionalities and is also used to relay specific attacks from the compromised devices such as DDoS or vulnerability exploitation campaigns. It seems to be used to gather intelligence from the networks associated with the compromised edge devices.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
GobRAT, which has been already documented by the JP-CERT, is a swiss-army knife backdoor written in Go which has standard RAT functionalities and is also used to relay specific attacks from the compromised devices such as DDoS or vulnerability exploitation campaigns. It seems to be used to gather intelligence from the networks associated with the compromised edge devices.
GobRAT, which has been already documented by the JP-CERT, is a swiss-army knife backdoor written in Go which has standard RAT functionalities and is also used to relay specific attacks from the compromised devices such as DDoS or vulnerability exploitation campaigns. It seems to be used to gather intelligence from the networks associated with the compromised edge devices.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
GobRAT uses TLS to send and receive data with its C2 server.
Start socks5 ... Execute SOCKS5 proxy with specified port and password ... Execute SOCKS5 proxy on specified port
40 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote Access Trojan (RAT) associated with China-nexus infrastructure, referenced in context of shared C2 infrastructure.
Referenced as malware associated with China-nexus threat actors on IPs hosting the same certificate observed in Bulbature-related infrastructure.
GobRAT is a remote access trojan (RAT) and anonymization tool that infects hosts, allowing threat actors to use compromised systems as operational nodes for launching attacks, thereby masking their true infrastructure. It is assessed to be used exclusively by Chinese state-sponsored threat groups.
GobRAT is referenced only as infrastructure with weak overlap used in attribution analysis; the content does not describe its functionality further.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.