logo

Report: Newly Discovered GlassRAT Lurked For Years, Undetected

ID: 027267ee-3e99-51d5-9e7d-66d827f001da

STIX ID: report--027267ee-3e99-51d5-9e7d-66d827f001da

Feed Name: Security Ledger

Threat Score
78/100

Date Published: 2015-11-24

Date Updated: 2026-04-26

Author: Paul Roberts

...
...

RSA Security discovered GlassRAT, a remote-access trojan reportedly active since 2012 and operating stealthily for nearly three years, which targets Chinese nationals at large multinational corporations; the threat uses a dropper masquerading as Adobe Flash (Flash.exe) and a malicious DLL signed with a legitimate/compromised certificate to evade detection, and RSA links it to prior families (Mirage, Magicfire, PlugX), suggesting a sophisticated, persistent espionage campaign.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.