Remote Access Trojan (RAT)
A remote access trojan is malware that gives an attacker covert, ongoing control of a victim's device — keyboard, files, camera and credentials included.
A remote access trojan (RAT) is malware that hands an attacker persistent, covert control of an infected device, as if they were sitting at it. Where an infostealer grabs what it can and leaves, a RAT stays: it can log keystrokes, browse and exfiltrate files, capture the screen and webcam, install further malware, and pivot deeper into the network — all while the machine appears to behave normally. Commodity families such as AsyncRAT, XWorm, and NetSupport (a legitimate remote-admin tool routinely abused) circulate cheaply in criminal markets, which puts full remote control within reach of low-skill attackers.
How it works
The "trojan" half of the name is the delivery: the victim installs it believing it is something else. Common routes are phishing attachments and links, cracked software and game cheats, malicious ads, and paste-and-run lures like ClickFix, where the user is talked into executing the installation command personally — Microsoft lists several RAT families among the most common ClickFix payloads, a chain we unpack in our ClickFix guide. Once running, the RAT connects outward to the attacker's command-and-control server, which lets it slip through firewalls that allow outbound traffic. From there the operator works interactively: harvesting credentials, staging data, deploying ransomware, or quietly watching. A related social-engineering variant skips the malware entirely — tech support scammers talk victims into installing legitimate remote-access software and achieve the same control with a signed binary.
How to defend against it
Endpoint detection and response catches known families and the behaviors — persistence mechanisms, unusual outbound connections — that betray unknown ones. Application allowlisting and blocking unapproved remote-admin tools close the legitimate-software loophole, and egress filtering can cut off command-and-control traffic. But because a RAT nearly always arrives by persuasion rather than exploit, the human layer decides most outcomes: teach employees that unexpected installers, "fix it yourself" command prompts, and unsolicited remote-assistance requests are attack patterns, and rehearse those scenarios in phishing simulations alongside classic email lures.
Related terms
NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.
Book a demo