Microsoft Word - GlassRAT final layout pmb-2015-11-22.docx
ID: 207608f8-0437-4d4d-bd59-8e8aef0cddd7
STIX ID: report--207608f8-0437-4d4d-bd59-8e8aef0cddd7
Threat Score
85/100
Uploaded: 2026-08-07
Published Date: 2015-11-23
Last Modified Date: 2015-11-23
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
RSA Research describes GlassRAT, a stealthy Remote Administration Trojan (RAT) that evades many antivirus products, is delivered via signed droppers (abusing a compromised code‑signing certificate), and provides reverse‑shell, file transfer and command execution capabilities; the report details installation/persistence, C2 protocol and hosts, YARA signature/IOCs, and highlights C2 infrastructure overlap with other Asia‑focused espionage campaigns, suggesting targeted activity against Chinese nationals and organizations.
