Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-05 18:51:28 UTC Home > List all groups > List all tools > List all groups using tool FakeM Tool: FakeM Names FakeM FakeM RAT Terminator RAT Category Malware Type Backdoor Description (Trend Micro) We found a family of RATs that we call “FAKEM” that make their network traffic look like various protocols. Some variants attempt to disguise network traffic to look like Windows® Messenger and Yahoo!® Messenger traffic. Another variant tries to make the content of its traffic look like HTML. While the disguises the RATs use are simple and distinguishable from legitimate traffic, they may be just good enough to avoid further scrutiny. Information MITRE ATT&CK Malpedia AlienVault OTX Last change to this tool card: 14 May 2020 Download this tool card in JSON format All groups using tool FakeM Changed Name Country Observed APT groups https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=821cb159-baed-4d8b-9ac4-5740abcd6b2b Page 1 of 2 Scarlet Mimic 2015-Aug 2022   1 group listed (1 APT, 0 other, 0 unknown) Source: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=821cb159-baed-4d8b-9ac4-5740abcd6b2b https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=821cb159-baed-4d8b-9ac4-5740abcd6b2b Page 2 of 2