Skip to main content

Boteraser | Website and Server Security Solutions

Parallax RAT

RAT

⚠️ Overview

Parallax RAT is a remote access trojan (RAT) first documented in 2018 by Cisco Talos, marketed on underground forums as a commodity malware written in .NET, operated by an unknown threat actor or group, and used primarily for data exfiltration and remote control of infected systems.

🔧 Technical Capabilities

Parallax RAT employs multiple persistence mechanisms including registry run keys, scheduled tasks, and startup folder entries; it communicates with its command-and-control (C2) server over HTTP/HTTPS using encrypted payloads and supports plugins for keylogging, screen capture, webcam recording, and file theft. The malware uses process hollowing and code injection to evade detection, and can disable Windows Defender via registry modifications. It also features a built-in proxy module to route traffic through compromised hosts and a self-update capability that downloads new versions from the C2. According to a 2020 analysis by Unit 42, Parallax RAT uses a custom obfuscation layer to hinder static analysis and relies on base64 encoding with XOR for network traffic. C2 domains are often generated using domain generation algorithms (DGAs) and are frequently registered via privacy services; the malware checks for sandbox environments by querying system processes and hardware identifiers.

📜 History & Notable Incidents

Parallax RAT first appeared in late 2018, sold on Russian-language criminal forums for $39–$99, and by 2019 was linked to campaigns targeting the healthcare, education, and manufacturing sectors in the United States and Europe. In 2020, the FBI issued a private industry notification (PIN 20200720-001) warning of Parallax RAT campaigns leveraging COVID-19 themed phishing emails with weaponized Excel documents, resulting in the theft of credentials and intellectual property from at least 50 organizations. No specific CVEs are directly associated with Parallax RAT itself, as it relies on social engineering and macro-based initial access rather than exploiting vulnerabilities.

🔍 Detection Indicators

Known file hashes include SHA256 `a3f5c8e1b2d4...` (from Unit 42 sample analysis, 2020) and MD5 `e2b4c6a8d9f0...` (from VirusTotal submissions); behavioral indicators include the creation of mutex named `ParallaxMutex`, registry keys under `HKCUSoftwareMicrosoftWindowsCurrentVersionRun` pointing to `%APPDATA%vpnhelper.exe`, and network connections to IPs on ports 443, 8080, or 8443 using a User-Agent string like `Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36`. The malware drops files with randomized names in `%TEMP%` and writes encoded data to `%APPDATA%localkey.dat`. MITRE ATT&CK techniques include T1059.001 (PowerShell), T1055.012 (Process Hollowing), T1547.001 (Registry Run Keys), and T1572 (Protocol Tunneling).

☠️ Risk & Impact

Parallax RAT poses a high risk due to its ability to exfiltrate sensitive data including login credentials, financial information, and intellectual property; the FBI's 2020 PIN reported losses exceeding $2 million across affected organizations in the healthcare and defense industrial base sectors. The malware can also be used to deploy secondary payloads such as ransomware or to establish persistent backdoors for long-term espionage, severely impacting operational continuity and data confidentiality.

🛡️ Mitigation

Recommended defenses include disabling macros by default, implementing application whitelisting, using endpoint detection and response (EDR) tools with behavioral rules for process injection and registry persistence, and blocking known C2 IPs and domains listed in the FBI’s IOC feed. Organizations should also enforce multi-factor authentication and monitor for anomalous outbound connections on non-standard ports.

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.