MASOL RAT is a cross-platform remote access trojan and backdoor associated with China-aligned cyberespionage activity, particularly clusters overlapping with Earth Estries and related operations targeting Southeast Asian government and telecommunications environments. It has been documented as an HTTP-based Windows backdoor and has also been observed on Linux devices, indicating support for both Windows and Linux operations. MASOL RAT has been used in long-running intrusion sets focused on maintaining covert access to sensitive networks rather than causing disruption.
The malware provides core remote administration capabilities including arbitrary command execution, file upload and download, configuration updates, and backdoor access for follow-on operations. Reporting also attributes keylogging and in-memory payload execution to MASOL RAT in some campaigns, showing its role not only as an access tool but also as a collection and post-exploitation component. In observed intrusions, MASOL RAT was deployed alongside other espionage tooling such as EggStremeFuel, EggStreme Loader, Gorem RAT, TrackBak Stealer, and additional loaders and stealers, suggesting it is part of a broader modular toolkit used to establish persistence, collect information, and support lateral operational objectives.
MASOL RAT has been linked to campaigns against Southeast Asian government networks and to broader Earth Estries activity affecting telecommunications, government, and related service-provider ecosystems across multiple regions. It has also been discussed in connection with exploitation of internet-facing infrastructure, although some specific attribution and delivery-path claims remain low confidence. High-confidence reporting supports its use as an espionage-oriented backdoor within multi-stage intrusions conducted by China-linked threat actors.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Sophos Firewall RCE [CVE-2022-3236] ... Exploitable via the User Portal or Webadmin, allowing remote code execution without authentication. ... Trend Micro’s research on Salt Typhoon ... noted a potential connection to this vulnerability, stating they “currently only have low confidence that Earth Estries has previously deployed the MASOL RAT through CVE-2022-3236” | Trend Micro’s research on Salt Typhoon (dubbed “Earth Estries”) noted a potential connection to this vulnerability, stating they “currently only have low confidence that Earth Estries has previously deployed the MASOL RAT through CVE-2022-3236”
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Trend Micro’s research on Salt Typhoon (dubbed “Earth Estries”) noted a potential connection to this vulnerability, stating they “currently only have low confidence that Earth Estries has previously deployed the MASOL RAT through CVE-2022-3236”
Attackers deployed numerous malware families, including HIUPAN, PUBLOAD, EggStremeFuel, MASOL RAT, PoshRAT, TrackBak Stealer, Hypnosis Loader, and FluffyGh0st.
Attackers deployed numerous malware families, including HIUPAN, PUBLOAD, EggStremeFuel, MASOL RAT, PoshRAT, TrackBak Stealer, Hypnosis Loader, and FluffyGh0st.
Attackers deployed numerous malware families, including HIUPAN, PUBLOAD, EggStremeFuel, MASOL RAT, PoshRAT, TrackBak Stealer, Hypnosis Loader, and FluffyGh0st.
Masol RAT and EggStreme Loader provided backdoor access, keylogging, and in-memory payload execution, while TrackBak stole keystrokes, clipboard data, and network info.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
Variants of PUBLOAD use either HTTP or TCP for command-and-control (C2) communications. The sample we observed is a variant that uses TCP... Masol RAT... communicates with its C2 servers over HTTP POST... This malware uses Google Remote Procedure Call (gRPC) for C2 communication.
EggStremeFuel, a lightweight backdoor that's equipped to download/upload files... EggStremeLoader... supports 59 backdoor commands... This includes a variant that facilitates file download/upload over Dropbox. MASOL RAT... with file download/upload... COOLCLIENT... supports file download/upload.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote access trojan used in the campaign to provide persistent access to compromised systems.
A remote access trojan that provides backdoor access, keylogging, and in-memory payload execution.
Remote access trojan with file download/upload and arbitrary command execution capabilities.
HTTP-based Windows backdoor designed to run as a service DLL. It communicates with C2 over AES-encrypted HTTP POST and supports arbitrary command execution, C2 configuration management, and file upload/download.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.