Join our Newsletter — 33% off our NHI Course
Home Glossary Cyber Security LodaRAT
Cyber Security

LodaRAT

← Back to Glossary
By NHI Mgmt Group Updated September 1, 2026 Domain: Cyber Security

LodaRAT is a remote access trojan that gives an attacker control over an infected system while collecting data and maintaining persistence. In this article, it is notable for using phishing delivery, obfuscation, process injection, encrypted command and control, and session theft through saved passwords and browser cookies.

Expanded Definition

LodaRAT is a remote access trojan, or RAT, that combines covert access, persistence, and credential theft with delivery techniques designed to avoid attention. In security writing, it is best understood as an intrusion tool rather than a broad malware category, because its value to an attacker comes from remote control, post-compromise visibility, and the ability to blend into normal user activity. The term is used in the broader cyber domain to describe malware that can harvest data, manipulate files, and maintain operator access through multiple rounds of command and control.

Its importance is not only the malware itself, but the tradecraft around it: phishing is often used to gain the first foothold, obfuscation slows detection, process injection hides malicious actions inside trusted processes, and encrypted command and control reduces network inspection opportunities. The most common misapplication is treating LodaRAT as simple commodity malware, which occurs when defenders focus on the initial infection and miss the persistence and credential abuse that follow.

Examples and Use Cases

Implementing detection and response rigorously often introduces tuning overhead, requiring organisations to weigh broader telemetry coverage against alert volume and analyst fatigue.

For security teams, LodaRAT is usually discussed through the stages of an intrusion rather than as a standalone file or payload. That makes incident handling more effective when detections are tied to behaviour, identity use, and post-execution activity, as reflected in the NIST Cybersecurity Framework 2.0.

  • A phishing email delivers a malicious attachment that installs the RAT and opens a remote shell for the operator.
  • A compromised workstation is used to extract saved browser cookies and passwords, enabling lateral movement into email, VPN, or SaaS accounts.
  • Process injection is used to place malicious activity inside a trusted process, reducing the chance of straightforward endpoint detection.
  • Encrypted command and control keeps traffic from being obvious to basic network inspection, especially when the malware communicates in short, intermittent bursts.
  • Persistence mechanisms keep the attacker present after reboots or remediation attempts, which turns a single compromise into a recurring access problem.

Why It Matters for Security Teams

LodaRAT matters because it sits at the intersection of malware execution, credential compromise, and persistence, which means a narrow endpoint-only response often leaves the attacker’s access intact. Once browser cookies, saved passwords, or active sessions are stolen, the incident becomes an identity problem as much as a malware problem. That is why teams handling this threat need to think about account resets, session revocation, token invalidation, and scoping where the attacker may have moved after the initial payload executed.

For defenders, the practical risk is delayed recognition: a machine may appear cleaned while the attacker continues using harvested credentials from elsewhere. Behavioural monitoring, privileged account review, and careful containment all matter, but the decisive failure is usually incomplete trust boundary repair. Organisations typically encounter repeated re-entry, account abuse, or unexplained access only after the first cleanup fails, at which point LodaRAT becomes operationally unavoidable to address.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 provides the primary governance reference for this term.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0DE.CM-1RAT activity is a detectable event that fits continuous monitoring and anomaly detection.

Instrument endpoint and network telemetry to identify abnormal process, session, and C2 behaviour early.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 1, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org