Chaos RAT is an open-source, Go-based remote administration tool repurposed as a remote access trojan against Windows and Linux systems. Development began in 2017, and malicious deployment was observed by November 2022, including attacks against Linux cloud instances. It provides remote shell access, arbitrary command execution, host reconnaissance, screenshot capture, recursive directory browsing, file deletion, bidirectional file transfer, and host reboot or shutdown. Windows clients additionally support workstation locking and user sign-out. It also supports network traffic proxying.
Clients authenticate to command-and-control infrastructure using embedded JSON Web Tokens, report system information, and periodically poll for commands. Recent variants store configuration in Base64-encoded objects with randomized field names; some samples use UPX packing. Windows payloads can run with their interface hidden. These capabilities support surveillance, data exfiltration, and other post-compromise operations.
Distribution has included phishing links or attachments and malicious software packages. In 2025, malicious Arch User Repository packages presented as browser-related fixes installed Chaos RAT. The September 2026 DirtyBlanket supply-chain campaign distributed a modified Linux client through malicious npm packages impersonating Express and React libraries. That derivative used systemd-service persistence, system-service masquerading, immutable file attributes, and Tor-based command-and-control communications. The surrounding campaign separately stole SSH private keys and npm tokens to propagate through SSH-accessible hosts and compromised package repositories; those propagation mechanisms are not established as native Chaos RAT features.
Earlier Linux cryptojacking campaigns deployed Chaos RAT alongside XMRig, using separate scripts for persistence and payload retrieval. Chaos RAT itself provides remote control rather than cryptocurrency mining. Its observed deployments are not attributed to a named threat actor.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Cross Site Scripting vulnerability in tiagorlampert CHAOS v.5.0.1 allows a remote attacker to escalate privileges via the sendCommandHandler function in the handler.go component.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
The malware achieves its persistence by altering /etc/crontab file, a UNIX task scheduler that, in this case, downloads itself every 10 minutes from Pastebin.
When running, the RAT client connects to the C&C server via its address, and default port, using a JSON Web Token (JTW) for authorization.
Le backdoor communique via Tor (socks5://127.0.0.1:9050) vers un service caché .onion.
This was followed by routines for persistence and payload execution, which in most cases is a Monero (XMR) cryptocurrency miner.
the initial phase saw attackers trying to kill off competing malware, security products, and other cloud middleware.
29 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Outil open-source de remote-access trojan dont le client sert de base au backdoor systemd-fontd déployé dans cette campagne.
Referenced as an example of a malicious upload in AUR to illustrate software verification risks.
Open-source RAT variant used in attacks against Windows and Linux, reportedly distributed via fake network tool downloads.
Remote access trojan delivered via malicious Arch Linux AUR packages, providing remote control capability on infected systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.