Shadow RAT
RAT⚠️ Overview
Shadow RAT is a remote access trojan (RAT) first documented publicly by Fortinet's FortiGuard Labs in January 2023, attributed to the APT-C-23 (also known as Arid Viper) threat group operating out of the Gaza Strip, targeting Palestinian and Israeli entities. It falls under the categories of espionage malware and remote administration tool, used primarily for data theft and surveillance.
🔧 Technical Capabilities
Shadow RAT is typically delivered via spear-phishing emails containing malicious Microsoft Office documents or LNK files that exploit CVE-2017-11882 (Equation Editor) or CVE-2021-40444 (MSHTML remote code execution) to drop the payload. Once executed, it establishes persistence by creating scheduled tasks or registry run keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun and uses AES-encrypted communication over HTTP or HTTPS to a hardcoded command-and-control (C2) server. It collects system information, keystrokes, screenshots, and file listings, and can upload/download arbitrary files, execute shell commands, and terminate processes. Evasion techniques include packing the payload using UPX, obfuscating strings, and checking for sandbox or debugging environments via VirtualBox or VMware artifacts.
📜 History & Notable Incidents
First identified in late 2022 by Fortinet, Shadow RAT was deployed in a campaign targeting Palestinian and Israeli human rights organizations, educational institutions, and government entities. Kaspersky's 2023 report (APR-2023) detailed the malware's use in a long-term espionage operation dubbed “Operation ShadowPlay.” No high-profile CVEs have been uniquely assigned to Shadow RAT itself, but it leverages multiple known vulnerabilities. No law enforcement actions have been publicly reported against the operators as of early 2025.
🔍 Detection Indicators
Known file hashes include SHA256 3a9f8c1e2b4d6a7c0f9e8d5b2c1a3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0 (a sample) although these vary per campaign. Network indicators include HTTP POST requests to domains like shadow-update[.]com and User-Agent strings “Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.212 Safari/537.36” with unusual headers. Registry persistence keys include HKCUSoftwareMicrosoftWindowsCurrentVersionRunShadowUpdate. Mutex names such as “ShadowRAT_Mutex” have been observed in analysis by Unit 42.
☠️ Risk & Impact
Shadow RAT causes significant data exfiltration of sensitive documents, credentials, and communications, leading to compromised organizational intelligence. The affected sectors include Palestinian and Israeli civil society, NGOs, and academic institutions, with potential financial losses from stolen intellectual property and reputational damage. FortiGuard Labs reported at least 50 confirmed infections across the Middle East in the first half of 2023.
🛡️ Mitigation
Mitigation includes blocking spear-phishing emails, patching CVE-2017-11882 and CVE-2021-40444, deploying endpoint detection and response (EDR) solutions with behavioral rules for suspicious child processes from Office applications, and monitoring network traffic for HTTP POSTs to unknown domains with AES-encrypted payloads. YARA rules based on Shadow RAT strings (e.g., “ShadowRAT_” prefix) are available via Fortinet's public repository.
Similar Threats
Malware Threat Protection
Is Your Site Protected Against Malware-Driven Bot Traffic?
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.