← All terms

Remote Access Trojan (RAT)

A remote access trojan is malware that gives an attacker covert, ongoing control of a victim's device — keyboard, files, camera and credentials included.

A remote access trojan (RAT) is malware that hands an attacker persistent, covert control of an infected device, as if they were sitting at it. Where an infostealer grabs what it can and leaves, a RAT stays: it can log keystrokes, browse and exfiltrate files, capture the screen and webcam, install further malware, and pivot deeper into the network — all while the machine appears to behave normally. Commodity families such as AsyncRAT, XWorm, and NetSupport (a legitimate remote-admin tool routinely abused) circulate cheaply in criminal markets, which puts full remote control within reach of low-skill attackers.

How it works

The "trojan" half of the name is the delivery: the victim installs it believing it is something else. Common routes are phishing attachments and links, cracked software and game cheats, malicious ads, and paste-and-run lures like ClickFix, where the user is talked into executing the installation command personally — Microsoft lists several RAT families among the most common ClickFix payloads, a chain we unpack in our ClickFix guide. Once running, the RAT connects outward to the attacker's command-and-control server, which lets it slip through firewalls that allow outbound traffic. From there the operator works interactively: harvesting credentials, staging data, deploying ransomware, or quietly watching. A related social-engineering variant skips the malware entirely — tech support scammers talk victims into installing legitimate remote-access software and achieve the same control with a signed binary.

How to defend against it

Endpoint detection and response catches known families and the behaviors — persistence mechanisms, unusual outbound connections — that betray unknown ones. Application allowlisting and blocking unapproved remote-admin tools close the legitimate-software loophole, and egress filtering can cut off command-and-control traffic. But because a RAT nearly always arrives by persuasion rather than exploit, the human layer decides most outcomes: teach employees that unexpected installers, "fix it yourself" command prompts, and unsolicited remote-assistance requests are attack patterns, and rehearse those scenarios in phishing simulations alongside classic email lures.

Related terms

ClickFixClickFix is a social engineering attack that uses fake CAPTCHAs or error prompts to trick victims into pasting and running malicious commands themselves.KeyloggerA keylogger is software or hardware that secretly records keystrokes to steal passwords, messages, and card numbers, feeding credential-based attacks.SpywareSpyware is malicious software that covertly monitors a device — harvesting credentials, messages, and activity — and feeds social-engineering attacks.Tech Support ScamA tech support scam impersonates IT or vendor support to gain remote access or payment, often via fake virus pop-ups, cold calls, or search ads.
See your Human Risk Score

NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.

Book a demo