logo

Moonrise RAT: A New Low-Detection Threat with High-Cost Consequences

ID: d279bd4f-c4dc-5781-8441-3573e3d05a4a

STIX ID: report--d279bd4f-c4dc-5781-8441-3573e3d05a4a

Feed Name: ANY.RUN's Cybersecurity Blog

Threat Score
75/100

Date Published: 2026-02-24

Date Updated: 2026-04-26

Author: ANY.RUN

...
...

This report analyzes Moonrise, a stealthy Go-based RAT that initially bypassed static detection and rapidly established WebSocket C2 connectivity; it documents observed commands and capabilities (process/file enumeration, remote execution, credential/clipboard theft, screen/webcam/audio capture, persistence and lifecycle management), provides multiple sample hashes and a C2 IP, and recommends behavior-based monitoring, sandbox execution, and TI-enrichment for earlier detection and containment.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.