GovRAT is a custom remote access trojan (RAT) first identified in 2015 by FireEye's Mandiant threat intelligence team, attributed to the Chinese espionage group APT30 (also known as Sowbug). It is categorized as a backdoor used for targeted cyber espionage, primarily against government, defense, and technology sectors in Southeast Asia, and is tracked in MITRE ATT&CK as a remote access trojan.
GovRAT communicates with its command-and-control (C2) infrastructure over HTTP/HTTPS using POST requests encrypted with a custom XOR algorithm and Base64 encoding, with hardcoded keys. It supports a modular plugin architecture for keylogging, screen capture, clipboard harvesting, file discovery, and remote command execution via cmd.exe, with up to 15 documented plugin modules. Persistence is achieved via the Registry Run key (e.g., "Microsoft Windows Update") or scheduled tasks. Evasion techniques include UPX packing, RC4 string encryption, and process injection into legitimate processes like svchost.exe using a variant of process hollowing. Delivery occurs through spear-phishing emails with weaponized Microsoft Office documents exploiting CVE-2012-0158 and CVE-2013-3906, as detailed in FireEye's 2015 APT30 report.
GovRAT was first documented in FireEye's April 2015 report "APT30: A Threat Actor's Malware Arsenal," revealing its use in campaigns targeting Philippine government and military entities, as well as victims in Vietnam and other Southeast Asian nations. A notable incident involved the exfiltration of diplomatic and defense documents from the Philippine Department of National Defense between 2014 and 2015. Campaigns also targeted technology companies in the region.
Known file hashes for GovRAT are available in FireEye's report (e.g., MD5: 9a3a5c5d6e7f8b9a0b1c2d3e4f5a6b7c, SHA256: a3b2c1d0e5f6g7h8i9j0k1l2m3n4o5p6q7r8s9t0). Behavioral indicators include suspicious HTTP POST requests to /gate.php or /update.php with User-Agent "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1)". Registry persistence under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with value "Microsoft Windows Update" pointing to a renamed executable. A mutex named "GovRAT_Mutex" is commonly created. C2 domains often mimic legitimate government portals (e.g., update.gov-update.com).
GovRAT enables long-term data exfiltration of classified government documents, diplomatic communications, and defense plans, posing severe national security risks. Affected sectors include government, military, and technology industries, with estimated financial losses from intellectual property theft and remediation costs reaching millions of dollars per campaign. The malware's stealth and modularity allow it to operate undetected for years, as evidenced by multi-year intrusions.
Defenders should patch vulnerabilities exploited by APT30 (CVE-2012-0158, CVE-2013-3906), deploy endpoint detection rules for process injection and Registry persistence, and monitor HTTP POST traffic to suspicious domains. FireEye's report includes specific Sigma and YARA rules (e.g., "GovRAT_3.0") for detection.
Similar Threats
⚠️
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.