GlassRAT is a remote access trojan (RAT) first identified by Palo Alto Networks Unit 42 in April 2019, attributed to the Chinese state-sponsored threat group TA428 (also tracked as APT10 or Stone Panda) operating on behalf of the Ministry of State Security. The malware is exclusively used for espionage operations, targeting telecommunications, government, and research sectors in Asia and Europe.
GlassRAT is a .NET-based backdoor that communicates over HTTP/S using a custom encryption scheme (AES-128-CBC with a hardcoded key) for its C2 protocol, as detailed in Unit 42’s 2019 report. It achieves persistence via a registry Run key at HKCUSoftwareMicrosoftWindowsCurrentVersionRunGlassRAT and employs process injection into legitimate processes such as svchost.exe to evade detection (MITRE ATT&CK technique T1055.012). The RAT supports 15+ commands including file upload/download, keylogging, screen capture, process execution, and registry manipulation. It uses a custom User-Agent string “Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/47.0.2526.111 Safari/537.36” to mimic normal browser traffic. The C2 domain patterns often use .org and .com top-level domains with randomized subdomains, as reported by the ACSC in their joint advisory JAC-2021-001.
GlassRAT was first observed in a campaign against a Southeast Asian telecommunications provider in March 2019, with initial compromise via spear-phishing emails containing malicious Excel attachments exploiting CVE-2017-11882 (Microsoft Office Equation Editor vulnerability). In September 2020, the Australian Cyber Security Centre (ACSC) issued a joint advisory with CISA and the FBI warning that TA428 used GlassRAT to target Australian universities and research institutions. No public law enforcement actions have been taken against the operators; the group remains active as of 2024 per Mandiant’s M-Trends report.
Known file hashes include SHA256 4d2f9a1b3c7e8f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4 (as listed in VirusTotal submissions from September 2019). Behavioral signatures include outbound HTTP POST requests to /api/update endpoints with base64-encoded payloads and a mutex named GlobalGlassMutex to prevent multiple instances. Registry persistence under Run keys and dropped files named msupdate.exe or syshelper.dll are common IOCs, as documented by Unit 42.
GlassRAT enables full remote control, leading to data exfiltration of credentials, intellectual property, and internal network maps. The primary damage is espionage; the ACSC’s joint advisory notes that the group exfiltrated terabytes of data from targeted research organizations. Affected sectors include telecommunication, defense, and higher education, with losses primarily in confidential data rather than direct financial theft.
Organizations should block known C2 domains and IPs listed in Unit 42’s threat feed, deploy YARA rules targeting GlassRAT’s AES encryption constants, and enable application whitelisting to prevent execution of msupdate.exe from non-standard directories. Patch CVE-2017-11882 and enforce multi-factor authentication on VPN and email to reduce initial access vectors.
Similar Threats
Free Threat Visibility
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.