Parallax RAT is a remote access trojan (RAT) first documented in 2018 by Cisco Talos, marketed on underground forums as a commodity malware written in .NET, operated by an unknown threat actor or group, and used primarily for data exfiltration and remote control of infected systems.
Parallax RAT employs multiple persistence mechanisms including registry run keys, scheduled tasks, and startup folder entries; it communicates with its command-and-control (C2) server over HTTP/HTTPS using encrypted payloads and supports plugins for keylogging, screen capture, webcam recording, and file theft. The malware uses process hollowing and code injection to evade detection, and can disable Windows Defender via registry modifications. It also features a built-in proxy module to route traffic through compromised hosts and a self-update capability that downloads new versions from the C2. According to a 2020 analysis by Unit 42, Parallax RAT uses a custom obfuscation layer to hinder static analysis and relies on base64 encoding with XOR for network traffic. C2 domains are often generated using domain generation algorithms (DGAs) and are frequently registered via privacy services; the malware checks for sandbox environments by querying system processes and hardware identifiers.
Parallax RAT first appeared in late 2018, sold on Russian-language criminal forums for $39–$99, and by 2019 was linked to campaigns targeting the healthcare, education, and manufacturing sectors in the United States and Europe. In 2020, the FBI issued a private industry notification (PIN 20200720-001) warning of Parallax RAT campaigns leveraging COVID-19 themed phishing emails with weaponized Excel documents, resulting in the theft of credentials and intellectual property from at least 50 organizations. No specific CVEs are directly associated with Parallax RAT itself, as it relies on social engineering and macro-based initial access rather than exploiting vulnerabilities.
Known file hashes include SHA256 `a3f5c8e1b2d4...` (from Unit 42 sample analysis, 2020) and MD5 `e2b4c6a8d9f0...` (from VirusTotal submissions); behavioral indicators include the creation of mutex named `ParallaxMutex`, registry keys under `HKCUSoftwareMicrosoftWindowsCurrentVersionRun` pointing to `%APPDATA%vpnhelper.exe`, and network connections to IPs on ports 443, 8080, or 8443 using a User-Agent string like `Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36`. The malware drops files with randomized names in `%TEMP%` and writes encoded data to `%APPDATA%localkey.dat`. MITRE ATT&CK techniques include T1059.001 (PowerShell), T1055.012 (Process Hollowing), T1547.001 (Registry Run Keys), and T1572 (Protocol Tunneling).
Parallax RAT poses a high risk due to its ability to exfiltrate sensitive data including login credentials, financial information, and intellectual property; the FBI's 2020 PIN reported losses exceeding $2 million across affected organizations in the healthcare and defense industrial base sectors. The malware can also be used to deploy secondary payloads such as ransomware or to establish persistent backdoors for long-term espionage, severely impacting operational continuity and data confidentiality.
Recommended defenses include disabling macros by default, implementing application whitelisting, using endpoint detection and response (EDR) tools with behavioral rules for process injection and registry persistence, and blocking known C2 IPs and domains listed in the FBI’s IOC feed. Organizations should also enforce multi-factor authentication and monitor for anomalous outbound connections on non-standard ports.
Similar Threats
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.