Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-06 03:23:12 UTC Home > List all groups > List all tools > List all groups using tool MASOL RAT Tool: MASOL RAT Names MASOL RAT Backdr-NQ Category Malware Type Backdoor Description (Trend Micro) We discovered that Earth Estries uses another cross-platform backdoor, which we initially identified during our investigation of Southeast Asian government incidents in 2020. We named it MASOL RAT based on its PDB string. We couldn’t link MASOL RAT to any known threat group at the time due to limited information. However, this year we observed that Earth Estries has been deploying MASOL RAT on Linux devices targeting Southeast Asian government networks. Information Last change to this tool card: 28 December 2024 Download this tool card in JSON format All groups using tool MASOL RAT Changed Name Country Observed APT groups   Salt Typhoon, GhostEmperor 2020-Feb 2025 1 group listed (1 APT, 0 other, 0 unknown) Source: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=af09c77a-dc2b-42e3-87cb-54bd83877493 https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=af09c77a-dc2b-42e3-87cb-54bd83877493 Page 1 of 1