
According to security researcher MalwareHunterTeam , a remote access Trojan called Parallax RAT is being distributed via malicious spam campaigns . Installing the RAT on victims' machines allows attackers to gain full control of the infected system.
Since December 2019, the researcher has been monitoring samples of the Parallax RAT, as they have appeared on VirusTotal and other related services.
With the low price of $65 per month, attackers prefer this particular malware to gain access to victims' computers and steal credentials and files or execute commands.
Attackers can use the stolen data to steal other information , gain access to online banking accounts, and spread the Parallax RAT to other victims.
Parallax RAT is sold on hacking forums
Since early December 2019, the Parallax RAT has been sold on hacking forums. developers promote the tool and offer support to users.
Parallax hackers promote the product by saying that it is 99% reliable and suitable for both professionals and beginners.
The Parallax RAT has been developed by a hacking team, whose goal was to create the best tool for remote administration.
“Parallax RAT will provide you with everything you need. Suitable for professionals as well as beginners. First of all, we offer 99% reliability in terms of stability. Parallax RAT was designed to provide the user with a truly multi-layered performance and fast speed with minimal resource consumption. We are a team of developers and we are here to provide quality services,” says the team behind Parallax RAT.
Attackers can purchase a license to use the RAT for one month for just $65 or for three months for $175.
What does Parallax RAT promise?
- Credential theft
- Remote desktop capabilities
- Uploading and downloading files
- Executing remote commands on the infected computer
- Encrypted connections
- Windows XP support through Windows 10
Hackers also claim that the software is able to bypass Windows Defender, Avast, AVG, Avira, Eset, and BitDefender. However, this is probably not the case, as the RAT has been detected.
Distribution via malicious emails
Parallax RAT can spread in a variety of ways, but researchers have observed that it is mainly distributed via spam emails with malicious attachments.
For example, in the message below, hackers pose as a company that wants to purchase products.
If the victim opens the malicious attachment, the vulnerability Microsoft Office Equation Editor (CVE-2017-11882) is exploited. If the content is enabled, malicious macros will be executed to install the RAT.

Hackers use a variety of methods. They either use intermediate loaders or directly install the Parallax RAT on the computer.
At least two researchers have found a loader that downloads an image from the Imgur image sharing site. The image contains an embedded Parallax executable. This executable is extracted from the image and executed on the computer.
The RAT is then copied to another place and executed in other processes.
Once installed, a shortcut is created in the Windows Startup folder, so that it runs automatically when a user logs on to the system.
This allows attackers to access the computer whenever they want.
Once the Parallax RAT is installed, attackers can steal stored passwords and files, execute commands, and gain full control of the computer.
For many of the Parallax samples, the command & control servers are hosted on the free DNS server duckdns.org.
The best way to protect yourself from this type of malware is to avoid emails from unknown sources. Users should always be very careful and not open suspicious emails and attachments.
