GobRAT Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
1
occurrences
First Seen
January 8, 2026
Last Seen
January 8, 2026

GobRAT is a Windows remote access Trojan (RAT) that has been observed in campaigns attributed to China-linked threat actors.

Overview

GobRAT is a Windows remote access Trojan (RAT) that has been observed in campaigns attributed to China-linked threat actors. It provides remote control and data collection capabilities, enabling operators to maintain footholds in networks and perform reconnaissance or lateral movement. Its significance stems from its use by state-aligned groups and its continued deployment across campaigns as a flexible modular tool.

Related Threat Clusters

  • China-linked Cyber Group Expands Targeting to Southeastern Europe

    A sophisticated threat actor known as UAT-7290, tracked by Cisco Talos, has expanded its operations to target telecommunications providers in Southeastern Europe. This group, which has been active since at least 2022,…

    1 article · Updated January 8, 2026

Recent Intelligence Reports

  • New China — Bleepingcomputer · January 8, 2026

CVSS v3.1 Breakdown