MetaRAT Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
3
occurrences
First Seen
December 9, 2025
Last Seen
December 9, 2025

MetaRAT is a malware family used by threat actors to gain remote access to compromised systems.

Overview

MetaRAT is a malware family used by threat actors to gain remote access to compromised systems. Recent activity shows it being deployed through exploits targeting Ivanti Connect Secure VPN appliances, highlighting the risk of exposed VPN infrastructure and the importance of promptly patching vulnerabilities and monitoring for intrusions. The campaigns indicate a focus on delivering backdoor capabilities via VPN vulnerabilities to establish footholds in targeted networks.

Related Threat Clusters

Recent Intelligence Reports

  • Hackers Exploiting Vulnerabilities in Ivanti Connect Secure to Deploy MetaRAT Malware — Cybersecuritynews · December 9, 2025
  • Hackers Deploy MetaRAT Malware Through Ivanti Connect Secure Vulnerabilities — Cyberpress · December 9, 2025
  • Hackers Exploit Ivanti Connect Secure Vulnerabilities to Spread MetaRAT Malware — Gbhackers · December 9, 2025

CVSS v3.1 Breakdown