Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Attacks mounted by [Hacking Cat] have weaponized vulnerabilities in Exchange servers (e.g., CVE-2021-26855 and CVE-2026-42897) to deliver a Go-based remote access trojan dubbed Gorilla RAT. | Hacking Cat weaponized Exchange Server vulnerabilities to deliver a Go-based remote-access trojan dubbed Gorilla RAT.
Attacks mounted by [Hacking Cat] have weaponized vulnerabilities in Exchange servers (e.g., CVE-2021-26855 and CVE-2026-42897) to deliver a Go-based remote access trojan dubbed Gorilla RAT. | Hacking Cat weaponized Exchange Server vulnerabilities to deliver a Go-based remote-access trojan dubbed Gorilla RAT.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Hacking Cat weaponized Exchange Server vulnerabilities to deliver a Go-based remote-access trojan dubbed Gorilla RAT.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
Gorilla RAT написан на Go с использованием WebSocket; после запуска расшифровывает адрес C2, регистрирует жертву и ожидает команды.
The custom tool can tunnel network traffic, allowing attackers to remotely access systems inside a victim’s network.
Kaspersky said it discovered... a previously undocumented remote-access tool dubbed Gorilla RAT... The custom tool can tunnel network traffic, allowing attackers to remotely access systems inside a victim’s network.
12 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Go-based remote-access trojan that connects to a remote server, registers the victim, executes commands, enumerates processes, collects system information, transfers files, and opens or closes TCP tunnels for internal-network access.
Remote-access trojan used in Hacking Cat operations. It tunnels network traffic and supports lateral movement in victim networks after compromise of Microsoft Exchange servers.
A custom remote-access tool used after initial access to tunnel network traffic and enable remote access to systems inside a victim network.
A Go-based WebSocket remote-access trojan used by Hacking Cat. It establishes persistent C2 communications, registers host metadata, accepts remote commands, uploads and downloads files, executes shell commands, manages processes, enumerates directories and system information, and proxies traffic through TCP tunnels to access internal victim-network services. Some variants support VNC-based interactive control and employ sandbox/debugger-evasion checks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.