RAT

SparkRAT

SparkRAT (Spark) is an open-source Go remote-access framework with a self-hosted controller that generates configured endpoint clients. It offers remote terminal, desktop, screenshot, file, and process functions. Public reporting has documented malicious SparkRAT deployments; that does not make every deployment of the upstream dual-use project malicious.

Tool overview

Category
RAT
Research authors
Michael Haag
Created
2026-09-28
Last modified
2026-09-28
Privileges
Elevated privileges may be required for OS power actions; the upstream client has no fixed default service or persistence installer.
Free / availability
Yes
Verification required
Static review of pinned upstream source and public incident reporting; no local binary, controller, or sample execution was performed. The pinned upstream client build script establishes Windows and Linux builds. Hunt.io documents malicious macOS SparkRAT activity, including the campaign-specific artifacts recorded below; it does not establish a default upstream macOS installer or persistence path.
Supported platforms
LinuxWindowsmacOS

Capabilities

Self-hosted controller and configured endpoint generationRemote terminalRemote desktop and screenshotsFile managementProcess management

Executables & installation paths

Filename
Not recorded
OriginalFileName
Not recorded
Description
Not recorded

Installation paths

FORENSIC EVIDENCE

Disk artifacts

File
/Users/shared/pull.bin
Description
Campaign-specific downloaded SparkRAT client location documented by Hunt.io; not an upstream default path.
OS
macOS
File
/Users/run/com.second.startup.plist
Description
Campaign-specific LaunchAgent-style persistence artifact documented by Hunt.io; not an upstream default path.
OS
macOS

FORENSIC EVIDENCE

Network artifacts

Description
Endpoint connection values are generated per deployment and point to an operator-configured controller; no vendor domain is inherent to SparkRAT.
Domains
Not recorded
Ports
Not recorded

FORENSIC EVIDENCE

Other artifacts

Type
ConfiguredWebSocketRoute
Value
/ws
Type
ConfiguredUpdateRoute
Value
/api/client/update
Type
ClientUserAgentPrefix
Value
SPARK COMMIT:
Type
ControllerDefaultListenAddress
Value
:8000
Type
HuntIOMacOSSampleSHA256
Value
cd313c9b706c2ba9f50d338305c456ad3392572efe387a83093b09d2cb6f1b56
Type
HuntIOMacOSSampleSHA256
Value
52277d43d2f5e8fa8c856e1c098a1ff260a956f0598e16c8fb1b38e3a9374d15

References