RAT
SparkRAT
SparkRAT (Spark) is an open-source Go remote-access framework with a self-hosted controller that generates configured endpoint clients. It offers remote terminal, desktop, screenshot, file, and process functions. Public reporting has documented malicious SparkRAT deployments; that does not make every deployment of the upstream dual-use project malicious.
Tool overview
- Category
- RAT
- Research authors
- Michael Haag
- Created
- 2026-09-28
- Last modified
- 2026-09-28
- Privileges
- Elevated privileges may be required for OS power actions; the upstream client has no fixed default service or persistence installer.
- Free / availability
- Yes
- Verification required
- Static review of pinned upstream source and public incident reporting; no local binary, controller, or sample execution was performed. The pinned upstream client build script establishes Windows and Linux builds. Hunt.io documents malicious macOS SparkRAT activity, including the campaign-specific artifacts recorded below; it does not establish a default upstream macOS installer or persistence path.
- Supported platforms
Linux
Windows
macOS
Capabilities
Executables & installation paths
- Filename
- Not recorded
- OriginalFileName
- Not recorded
- Description
- Not recorded
Installation paths
FORENSIC EVIDENCE
Disk artifacts
- File
- /Users/shared/pull.bin
- Description
- Campaign-specific downloaded SparkRAT client location documented by Hunt.io; not an upstream default path.
- OS
- macOS
- File
- /Users/run/com.second.startup.plist
- Description
- Campaign-specific LaunchAgent-style persistence artifact documented by Hunt.io; not an upstream default path.
- OS
- macOS
FORENSIC EVIDENCE
Network artifacts
- Description
- Endpoint connection values are generated per deployment and point to an operator-configured controller; no vendor domain is inherent to SparkRAT.
- Domains
- Not recorded
- Ports
- Not recorded
FORENSIC EVIDENCE
Other artifacts
- Type
- ConfiguredWebSocketRoute
- Value
- /ws
- Type
- ConfiguredUpdateRoute
- Value
- /api/client/update
- Type
- ClientUserAgentPrefix
- Value
- SPARK COMMIT:
- Type
- ControllerDefaultListenAddress
- Value
- :8000
- Type
- HuntIOMacOSSampleSHA256
- Value
- cd313c9b706c2ba9f50d338305c456ad3392572efe387a83093b09d2cb6f1b56
- Type
- HuntIOMacOSSampleSHA256
- Value
- 52277d43d2f5e8fa8c856e1c098a1ff260a956f0598e16c8fb1b38e3a9374d15
References
- https://github.com/XZB-1248/Spark/blob/e2c8ce153d8494f7f1aa9999bfd86eef1bc6be79/README.md
- https://github.com/XZB-1248/Spark/blob/e2c8ce153d8494f7f1aa9999bfd86eef1bc6be79/scripts/build.client.sh
- https://github.com/XZB-1248/Spark/blob/e2c8ce153d8494f7f1aa9999bfd86eef1bc6be79/client/core/core.go
- https://github.com/XZB-1248/Spark/blob/e2c8ce153d8494f7f1aa9999bfd86eef1bc6be79/server/handler/handler.go
- https://www.sentinelone.com/labs/dragonspark-attacks-evade-detection-with-sparkrat-and-golang-source-code-interpretation/
- https://hunt.io/blog/sparkrat-server-detection-macos-activity-and-malicious-connections