GobRAT is a Windows remote access Trojan (RAT) that has been observed in campaigns attributed to China-linked threat actors.
GobRAT is a Windows remote access Trojan (RAT) that has been observed in campaigns attributed to China-linked threat actors. It provides remote control and data collection capabilities, enabling operators to maintain footholds in networks and perform reconnaissance or lateral movement. Its significance stems from its use by state-aligned groups and its continued deployment across campaigns as a flexible modular tool.
A sophisticated threat actor known as UAT-7290, tracked by Cisco Talos, has expanded its operations to target telecommunications providers in Southeastern Europe. This group, which has been active since at least 2022,…