BIOPASS RAT is a Windows remote access trojan associated with China-aligned intrusion activity and publicly linked to the FishMonger cluster, also tracked as Earth Lusca and Aquatic Panda. It has appeared alongside other tooling such as ShadowPad, Spyder, FunnySwitch, SprySOCKS, and Cobalt Strike in espionage-oriented operations. Reported campaigns tied to BIOPASS RAT have included watering-hole activity, including operations aimed at online gambling organizations, indicating its use in targeted intrusion sets rather than indiscriminate crimeware distribution.
The malware is used to provide remote access and post-compromise control on victim systems. It has been referenced in campaigns that reused code-signing material and operational techniques later seen in related China-aligned activity. Reporting has also noted behavioral similarities between BIOPASS RAT and other backdoors used in the same ecosystem, including localhost HTTP listener techniques that can support interaction with watering-hole scripts and victim-side infection checks.
Available information supports classifying BIOPASS RAT as part of a broader Chinese cyber-espionage toolset focused on stealthy access and sustained operations against selected targets. High-confidence public reporting in the supplied material does not provide a fuller capability breakdown for this malware beyond its role as a RAT and its use in targeted watering-hole campaigns against Windows environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Its toolkit already spanned ShadowPad, Cobalt Strike and the Biopass RAT...
The group uses a variety of TTPs including but not limited to LoTL tactics, phishing, ransomware, cryptocurrency mining, supply chain attacks, China Chopper, Gh0st RaT, PlugX, HighNoon, Derusbi, BioPass RAT, RedXOR, and ShadowPad.
The group uses a variety of TTPs including but not limited to LoTL tactics, phishing, ransomware, cryptocurrency mining, supply chain attacks, China Chopper, Gh0st RaT, PlugX, HighNoon, Derusbi, BioPass RAT, RedXOR, and ShadowPad.
1 distinct technique documented for this family, organized by ATT&CK tactic.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as part of FishMonger’s toolkit.
Named as part of FishMonger's wider espionage toolkit.
A remote access trojan listed as part of FishMonger’s toolset.
The group uses a variety of TTPs including but not limited to LoTL tactics, phishing, ransomware, cryptocurrency mining, supply chain attacks, China Chopper, Gh0st RaT, PlugX, HighNoon, Derusbi, BioPass RAT, RedXOR, and ShadowPad.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.