RAT

Overlord

Overlord is a publicly available cross-platform remote access framework with Go-based agents and a TypeScript/Node/Bun server. Operators manage agents via a web panel or Electron client over encrypted WebSocket (WSS) C2. Windows agents commonly masquerade as svchost, persist under AppData\Roaming\Microsoft\DeviceSync and the user Startup folder, and write HKCU Run values named OverlordAgent-*. Observed campaigns have routed C2 through ngrok tunnels. Supports Windows, Linux, and macOS.

Tool overview

Category
RAT
Research authors
Jose Hernandez
Created
2026-10-05
Last modified
2026-10-05
Privileges
User
Free / availability
Yes (publicly available / open source)
Verification required
Public GitHub project (doesntbreaktos/Overlord); ANY.RUN malware-trends write-up and sandbox task
Supported platforms
LinuxWindowsmacOS

Capabilities

Remote AccessEncrypted WebSocket (WSS) C2Persistence (Startup folder, Registry Run, Task Scheduler, WMI - build-dependent)Process / filename masqueradingCross-platform agentsWeb / Electron operator consoleOptional tunneling via operator-controlled services (e.g. ngrok)

Executables & installation paths

Filename
svchost-windows-amd64-*.exe
OriginalFileName
Not recorded
Description
Observed Go agent build naming pattern (platform-arch-hash) used for masquerading as svchost
Filename
svchost.exe
OriginalFileName
Not recorded
Description
Persistence copy name when DefaultStartupName/custom startup name is set to svchost
Filename
ovd_*.exe
OriginalFileName
Not recorded
Description
Default randomized Windows persistence executable prefix when no custom startup name is set
Filename
agent-*.exe
OriginalFileName
Not recorded
Description
Alternate agent filenames observed in ANY.RUN related tasks (e.g. agent-b97b.exe)
Filename
agent-*.tmp
OriginalFileName
Not recorded
Description
Temporary staging names written under DeviceSync and Startup during install/copy

Installation paths

*\AppData\Roaming\Microsoft\DeviceSync\svchost.exe
*\AppData\Roaming\Microsoft\DeviceSync\ovd_*.exe
*\AppData\Roaming\Microsoft\DeviceSync\agent-*.tmp
*\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\svchost.exe
*\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ovd_*.exe
*\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\agent-*.tmp
*\AppData\Roaming\Overlord\agent.exe
*\svchost-windows-amd64-*.exe
*\agent-windows-amd64-*.exe
ovd_*.exe

FORENSIC EVIDENCE

Disk artifacts

File
C:\Users\*\AppData\Roaming\Microsoft\DeviceSync\svchost.exe
Description
Windows persistence copy observed by ANY.RUN (custom startup name svchost). Public agent source uses AppData\Roaming\Microsoft\DeviceSync as the non-Startup install directory.
OS
Windows
File
C:\Users\*\AppData\Roaming\Microsoft\DeviceSync\ovd_*.exe
Description
Default randomized DeviceSync persistence binary prefix (ovd_ + hex) from public agent source.
OS
Windows
File
C:\Users\*\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\svchost.exe
Description
Startup-folder persistence copy observed by ANY.RUN for the analyzed Windows sample.
OS
Windows
File
C:\Users\*\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ovd_*.exe
Description
Default randomized Startup-folder persistence binary when no custom name is configured.
OS
Windows
File
C:\Users\*\AppData\Local\Temp\svchost-windows-amd64-*.exe
Description
Initial execution path pattern from ANY.RUN sandbox (e.g. svchost-windows-amd64-a8d100a3.exe).
OS
Windows
File
C:\Users\*\AppData\Roaming\Overlord\agent.exe
Description
Legacy install path retained in public agent source (getLegacyTargetPath).
OS
Windows
File
~/Library/Application Support/Overlord/*
Description
macOS agent support directory referenced by public persistence documentation/source.
OS
macOS
File
~/Library/LaunchAgents/*.plist
Description
macOS LaunchAgent persistence (build-dependent; label often com.* when custom startup name is set).
OS
macOS

FORENSIC EVIDENCE

Event log artifacts

EventID
4688
Description
Process creation for Overlord agent binaries (svchost-windows-amd64-*.exe, DeviceSync\svchost.exe, ovd_*.exe).
OS
Windows
EventID
1
Description
Sysmon process create for agent / persistence copies.
OS
Windows
EventID
11
Description
Sysmon file create under DeviceSync or Startup paths.
OS
Windows
EventID
13
Description
Sysmon registry value set for HKCU Run OverlordAgent-* persistence.
OS
Windows

FORENSIC EVIDENCE

Registry artifacts

Path
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OverlordAgent-*
Description
Autorun value observed by ANY.RUN as OverlordAgent-0ba8d3ca pointing to AppData\Roaming\Microsoft\DeviceSync\svchost.exe. Public source uses registry value prefix OverlordAgent- (plus legacy OverlordAgent).
OS
Windows
Path
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OverlordAgent
Description
Legacy registry value name from public agent source.
OS
Windows

FORENSIC EVIDENCE

Network artifacts

Description
Encrypted WebSocket (WSS) C2 to operator infrastructure. ANY.RUN observed the analyzed sample tunneling C2 via an ngrok hostname (cleavable-lucille-anagrammatically.ngrok... on 3.124.142.205:443 / TCP). ngrok itself is separately cataloged in LOLRMM and LOTTunnels.
Domains
  • *.ngrok-free.app
  • *.ngrok.app
  • *.ngrok.io
  • *.ngrok.com
  • pandoramods.top
  • savaliyapriyal874-code.github.io
Ports
  • 443
  • 5173

References

Acknowledgements

Person
ANY.RUN
Handle
@anyrun_app