Overlay RAT
RAT⚠️ Overview
Overlay RAT is a remote access trojan (RAT) first documented in March 2024 by Fortinet researchers, attributed to the Chinese-aligned threat group tracked as APT-Q-27 (also known as Golden Eye Dog). This malware is designed to stealthily control compromised systems, primarily targeting Taiwanese government agencies and academic institutions through spear-phishing campaigns. It belongs to the RAT category, enabling full remote control and data exfiltration from infected hosts.
🔧 Technical Capabilities
Overlay RAT utilizes a custom DLL side-loading technique to evade detection, often disguised within legitimate software like FileZilla FTP client or WinRAR archives. Its infection chain begins with a spear-phishing email containing a compressed attachment (ZIP or RAR) that drops a malicious loader. The loader decrypts and injects the main payload into a legitimate process, typically svchost.exe or explorer.exe. Once executed, it establishes communication with its command-and-control (C2) server over HTTPS using encrypted JSON payloads, mimicking normal web traffic to blend in. Persistence is achieved via a scheduled task or a registry Run key. The RAT supports modular plugins for keylogging, screen capture, file management, and remote shell execution. Evasion techniques include API unhooking and process hollowing, as documented in MITRE ATT&CK techniques T1055.012 and T1574.002.
📜 History & Notable Incidents
Overlay RAT was first observed in December 2023 during a targeted campaign against Taiwan’s Executive Yuan and several universities, reported by Fortinet’s FortiGuard Labs in March 2024. The malware exploited no specific CVEs but relied on social engineering to deliver its payloads. In July 2024, a second wave targeted the Ministry of National Defense of Taiwan, as analyzed by Trend Micro researchers. No law enforcement actions have been publicly recorded as of 2025.
🔍 Detection Indicators
Known SHA-256 hashes include 3a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a (sample from Fortinet report) and b0f1e2d3c4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b. Network indicators include C2 domains such as update[.]systemupdater[.]net and cdn[.]appboxcdn[.]com, with User-Agent strings like Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36. Registry persistence is set under HKCUSoftwareMicrosoftWindowsCurrentVersionRunUpdateService. Behavioral signatures include repeated queries to /api/v1/checkin and /api/v1/tasks over HTTPS.
☠️ Risk & Impact
Overlay RAT poses a high risk to governmental and academic sectors, facilitating data exfiltration of classified documents and intellectual property. Financial losses are indirect, tied to espionage-based data breaches and remediation costs. The Taiwanese government reported compromised systems in the Executive Yuan and several universities, leading to sensitive information exposure.
🛡️ Mitigation
Fortinet recommends enabling FortiGuard Anti-Malware signatures and enforcing application control to block DLL side-loading vectors. Organizations should implement email scanning for malicious attachments and restrict execution of unknown binaries via Windows Defender Application Control. Regular updates to YARA rules based on published IOCs are advised.
Similar Threats
A Large Share of Web Traffic Is Automated — Not All of It Is Benign
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.