s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-jar.sorillus

📛 Threat Title

Malware family: Sorillus RAT

Category: Sorillus RAT First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `jar.sorillus`. Printable name: Sorillus RAT.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain jar.sorillus VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/jar.sorillus

IOC database

Type
domain
Value
jar.sorillus
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-jar.sorillus

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/jar.sorillus

References (1)

Remediations (10)

  • web:bazaar.abuse.ch

    A malware sample can be associated with only one malware family . The page below gives you an overview on malware samples that MalwareBazaar has identified as SorillusRAT.

  • web:cybersecuritynews.com

    The Sorillus RAT itself represents a mature malware -as-a-service offering that was commercially available from 2019 until January 2025, when its official infrastructure was dismantled, potentially in connection with FBI Operation Talent.

  • web:github.com

    Sorillus RAT Sorillus RAT is a remote administration tool designed for managing client machines remotely. This project includes a server application to control clients and a client application that executes commands, captures screenshots, streams webcam, and manages files.

  • web:lolrmm.io

    Sorillus is a remote monitoring and management (RMM) tool. More information will be added as it becomes available.

  • web:malpedia.caad.fkie.fraunhofer.de

    Sorillus is a Java-based multifunctional remote access trojan ( RAT ) that targets Linux, macOS, and Windows operating systems. First created in 2019, the tool gained significant attention in 2022 when various obfuscated client versions began appearing on VirusTotal starting January 18, 2022.

  • web:malware-guide.com

    Sorillus is a type of malware called a Remote Access Trojan ( RAT ). It secretly enters a computer and allows a hacker to control it from far away. The hacker can see files, use the camera, record keystrokes, or steal personal information without the user knowing. Sorillus runs in the background, making it hard to notice, In order to remove Sorillus , you should run a complete system scan with a ...

  • web:www.esentire.com

    Sorillus is a moderately capable RAT but is unlikely to see success long-term due to availability of cracked versions and one-time purchase model. In contrast, the malware -as-a-service model used by the top infostealers such as as Redline or Raccoon Stealer generates generates reoccurring income.

  • web:www.itfunk.org

    Sorillus RAT is a sophisticated Java-based remote access trojan ( RAT ) marketed as malware‑as‑a‑service. It targets Windows, macOS, and Linux systems, enabling attackers to remotely control infected devices, steal credentials, capture webcam/mic, record keystrokes, and exfiltrate data—all while remaining stealthy.

  • web:www.pcrisk.com

    What kind of malware is Sorillus RAT ? Sorillus is a multifunctional remote administration trojan ( RAT ) based on Java that is offered as malware -as-a-service. The attackers behind Sorillus RAT use fake invoice-themed emails as their main method of delivering the malware . The developers offer the RAT for sale at €59.99 for lifetime access or at a discounted rate of €19.99. More about ...

  • web:www.bugsfighter.com

    What is Sorillus RAT Sorillus RAT is a sophisticated, Java-based remote access trojan offered as malware -as-a-service, targeting Windows, macOS, and Linux systems. Cybercriminals behind Sorillus RAT distribute it primarily through phishing emails containing fake invoices, which lure victims into downloading malicious files. Once installed, this RAT provides attackers with extensive control ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.