Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-05 14:48:27 UTC Home > List all groups > List all tools > List all groups using tool CrossRAT Tool: CrossRAT Names CrossRAT Trupto Category Malware Type Backdoor, Info stealer Description (The Hacker News) CrossRAT is a cross-platform remote access Trojan that can target all four popular desktop operating systems, Windows, Solaris, Linux, and macOS, enabling remote attackers to manipulate the file system, take screenshots, run arbitrary executables, and gain persistence on the infected systems. According to researchers, Dark Caracal hackers do not rely on any 'zero-day exploits' to distribute its malware; instead, it uses basic social engineering via posts on Facebook groups and WhatsApp messages, encouraging users to visit hackers-controlled fake websites and download malicious applications. CrossRAT is written in Java programming language, making it easy for reverse engineers and researchers to decompile it. Information MITRE ATT&CK Malpedia Last change to this tool card: 13 May 2020 Download this tool card in JSON format All groups using tool CrossRAT Changed Name Country Observed https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=1e267dbe-3c07-4764-9025-ab927fe63841 Page 1 of 2 APT groups   Dark Caracal 2007-Jun 2024   1 group listed (1 APT, 0 other, 0 unknown) Source: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=1e267dbe-3c07-4764-9025-ab927fe63841 https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=1e267dbe-3c07-4764-9025-ab927fe63841 Page 2 of 2