{
  "Name": "SparkRAT",
  "Category": "RAT",
  "Description": "SparkRAT (Spark) is an open-source Go remote-access framework with a self-hosted controller that generates configured endpoint clients. It offers remote terminal, desktop, screenshot, file, and process functions. Public reporting has documented malicious SparkRAT deployments; that does not make every deployment of the upstream dual-use project malicious.\n",
  "Author": "Michael Haag",
  "Created": "2026-09-28",
  "LastModified": "2026-09-28",
  "Details": {
    "Website": "https://github.com/XZB-1248/Spark",
    "PEMetadata": {
      "Filename": "",
      "OriginalFileName": "",
      "Description": ""
    },
    "Privileges": "Elevated privileges may be required for OS power actions; the upstream client has no fixed default service or persistence installer.",
    "Free": true,
    "Verification": "Static review of pinned upstream source and public incident reporting; no local binary, controller, or sample execution was performed. The pinned upstream client build script establishes Windows and Linux builds. Hunt.io documents malicious macOS SparkRAT activity, including the campaign-specific artifacts recorded below; it does not establish a default upstream macOS installer or persistence path.\n",
    "SupportedOS": [
      "Windows",
      "Linux",
      "macOS"
    ],
    "Capabilities": [
      "Self-hosted controller and configured endpoint generation",
      "Remote terminal",
      "Remote desktop and screenshots",
      "File management",
      "Process management"
    ],
    "Vulnerabilities": [],
    "InstallationPaths": []
  },
  "Artifacts": {
    "Disk": [
      {
        "File": "/Users/shared/pull.bin",
        "Description": "Campaign-specific downloaded SparkRAT client location documented by Hunt.io; not an upstream default path.",
        "OS": "macOS"
      },
      {
        "File": "/Users/run/com.second.startup.plist",
        "Description": "Campaign-specific LaunchAgent-style persistence artifact documented by Hunt.io; not an upstream default path.",
        "OS": "macOS"
      }
    ],
    "EventLog": [],
    "Registry": [],
    "Network": [
      {
        "Description": "Endpoint connection values are generated per deployment and point to an operator-configured controller; no vendor domain is inherent to SparkRAT.",
        "Domains": [],
        "Ports": []
      }
    ],
    "Other": [
      {
        "Type": "ConfiguredWebSocketRoute",
        "Value": "/ws"
      },
      {
        "Type": "ConfiguredUpdateRoute",
        "Value": "/api/client/update"
      },
      {
        "Type": "ClientUserAgentPrefix",
        "Value": "SPARK COMMIT: "
      },
      {
        "Type": "ControllerDefaultListenAddress",
        "Value": ":8000"
      },
      {
        "Type": "HuntIOMacOSSampleSHA256",
        "Value": "cd313c9b706c2ba9f50d338305c456ad3392572efe387a83093b09d2cb6f1b56"
      },
      {
        "Type": "HuntIOMacOSSampleSHA256",
        "Value": "52277d43d2f5e8fa8c856e1c098a1ff260a956f0598e16c8fb1b38e3a9374d15"
      }
    ]
  },
  "Detections": [],
  "References": [
    "https://github.com/XZB-1248/Spark/blob/e2c8ce153d8494f7f1aa9999bfd86eef1bc6be79/README.md",
    "https://github.com/XZB-1248/Spark/blob/e2c8ce153d8494f7f1aa9999bfd86eef1bc6be79/scripts/build.client.sh",
    "https://github.com/XZB-1248/Spark/blob/e2c8ce153d8494f7f1aa9999bfd86eef1bc6be79/client/core/core.go",
    "https://github.com/XZB-1248/Spark/blob/e2c8ce153d8494f7f1aa9999bfd86eef1bc6be79/server/handler/handler.go",
    "https://www.sentinelone.com/labs/dragonspark-attacks-evade-detection-with-sparkrat-and-golang-source-code-interpretation/",
    "https://hunt.io/blog/sparkrat-server-detection-macos-activity-and-malicious-connections"
  ],
  "Acknowledgement": []
}