Overlord RAT — Malware Profile
Overlord is an open-source, cross-platform remote access framework published on GitHub under the account vxaboveground, whose agents are written in Go and which state-aligned operators have adopted as a ready-made RAT. Agents call back to their operator over an encrypted WebSocket channel and support keylogging, screen and audio capture, webcam access, file system and process operations, script execution, a plugin system, self-update and remote desktop streaming. Proofpoint reported modified Overlord builds in the UNK_DeadDrop campaign of April-May 2026, a very likely North Korea-aligned cluster that phished developers with attacker-controlled GitHub and GitLab repositories, adding three custom modules for browser credential theft, cryptocurrency wallet collection and anti-forensic cleanup; the campaign binaries targeted Linux and macOS on both Intel and Apple Silicon, with Windows Overlord samples surfacing separately on VirusTotal. Jamf Threat Labs documented a fake Zoom installer that dropped a garble-obfuscated macOS Overlord agent persisting via a LaunchAgent.