A remote access Trojan (RAT) is a type of malware that disguises itself as legitimate software while silently granting an attacker full remote control over an infected system. RATs function as command-and-control (C2) tools, enabling attackers to pivot from a compromised machine into the broader network.
Remote Access Trojan (RAT)
Really, the name here, remote access Trojan or RAT, says it all: it's a Trojan that provides remote access. The Trojan part of this just means that it's misleading or deceptive, just like the Trojan horse. We have some sort of software that mimics other types of software. The end user might not see this visually, but maybe it's running in the background and appears as a different service.
What is it doing for us? It's giving us remote access to another system so we can control it. Because of this, I also like to think of it as a C2 type of software. So it's C2 malware that allows us to control another machine. I'd have a RAT that would be installed on this machine right here, and then I would control it from my machine, therefore getting access to the rest of the network.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →