Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Neptune RAT

117
Global rank
83 infographic chevron month
Month rank
75 infographic chevron week
Week rank
0
IOCs

Neptune RAT is a Visual Basic .NET remote access trojan that gives attackers full control over infected Windows machines while stealing credentials from 270+ applications, hijacking cryptocurrency transactions, spying on victims in real time, and, in its most destructive mode, wiping the operating system entirely. Marketed openly on GitHub, Telegram, and YouTube as the "Most Advanced RAT," it is distributed under a malware-as-a-service model.

RAT
Type
Unknown
Origin
1 February, 2025
First seen
11 August, 2026
Last seen

How to analyze Neptune RAT with ANY.RUN

RAT
Type
Unknown
Origin
1 February, 2025
First seen
11 August, 2026
Last seen

IOCs

IP addresses
48.209.138.168
23.59.18.102
162.159.142.9
74.178.240.61
57.153.246.3
48.192.1.64
107.172.232.84
2.23.246.9
2.16.204.141
20.165.94.54
20.190.159.130
48.209.138.189
172.211.123.248
23.216.77.25
23.52.181.141
48.209.6.48
135.232.92.137
135.232.92.97
2.23.246.101
184.30.158.70
Hashes
96ad1146eb96877eab5942ae0736b82d8b5e2039a80d3d6932665c1a4c87dcf7
bd2cc2f1f25b5f520a87068475247dd5611ab9f199ed3264983d720e016acf66
11e4532b5f32683ea255440abc55c86fdc21ea32af8549269198c1621b178e0d
a6836126dfea85e97110a2f5f654280f5bd31d8765a0accdf730d034a2258fef
5f989219b8d63d536a226033200079a311d825103e4ca6dbae8199c4426dd025
2e1bd155431ffd97949ed854b0982566e1234c941d7d8102de0958c316b3e4e8
4dbfc417d053ba6867308671f1c61f4dcafc61f058d4044db532da6d3bde3615
ecf13314c7d6c0b91e6c84b8bad95ec71cff55550d538395e256dd92643b307e
25e048300f6457d16ae92377c0bd427c2e40e8190258eb662cc7502229efbcb8
b10ceb923de2febce8fd3a347df4969bfe45477e887d78dce12443718c0e88aa
4e4ebce7bed44b7b361b88e3df497d0666db14caa46ba64ab799f4d99bdd5468
2dde25e8f58c7f2bdb1a7b5659e141602bd0d242fa4b7fa7b6ffb145b67faf96
ce353e77b40d084a22c638edcc18070d59a5113c8e94822e29ee3f49769f7ad9
3fb95c6e930d2bf5d79ef19d0e70cf98b099604103b0e204a141af5919c0d0db
21a00e1a549b20a45d4056eb82f37024a538ced37aee88e631fd4046ba7c1ebf
8619440329a9ca7de427b367a6ea33c56dd6cb12ef7f7688b8a1e79289377cea
d71c5a6293e15482840d0b34780b73362bb6a2309506a42792272021c540c9fe
6a29a585b0e9aac0ca67fc147f973fa15a8aacb5f4c2b97a22cac6cda9ec459e
e7c1950b289d79046c438ce88becc0c25686e3857dc5313ff7a7d73e6d82c88e
c67a1717eeadd1c6ee02ef77ace677af5e857dccc8bbefaa651e1e04669b6f0c
Domains
slscr.update.microsoft.com
www.microsoft.com
settings-win.data.microsoft.com
google.com
login.live.com
apostlejob3.duckdns.org
client.wns.windows.com
crl.microsoft.com
ocsp.digicert.com
fe3cr.delivery.mp.microsoft.com
activation-v2.sls.microsoft.com
go.microsoft.com
www.bing.com
edge-cloud-resource-static.azureedge.net
edge.microsoft.com
copilot.microsoft.com
bios-population-furniture-pillow.trycloudflare.com
msedge.b.tlu.dl.delivery.mp.microsoft.com
rechnungseinsicht.com
self.events.data.microsoft.com
URLs
https://settings-win.data.microsoft.com/settings/v3.0/wsd/waasassessment?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&ring=retail&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=bad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=10.0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=waasassessment&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&servicingbranch=cb&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&honorwufbdeferrals=0&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/micsecserca2011_2011-10-18.crl
https://go.microsoft.com/fwlink/?linkid=2257403&clcid=0x409
https://settings-win.data.microsoft.com/settings/v3.0/onesettings/client?osversionfull=10.0.19045.4046.amd64fre.vb_release.191206-1406&localdeviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&attrdataver=186&osuilocale=en-us&osskuid=48&app=wosc&appver=&isflightingenabled=0&telemetrylevel=1&devicefamily=windows.desktop
https://login.live.com/rst2.srf
https://login.live.com/ppsecure/deviceaddcredential.srf
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceaz1vqyrvgl0erhqlcpm8gy%3d
https://settings-win.data.microsoft.com/settings/v3.0/flightsettings/fsservice?processorclockspeed=3094&isretailos=1&oemmanufacturername=dell&flightingpolicyvalue=3&enablepreviewbuilds=4294967295&osversionfull=10.0.19045.4046.amd64fre.vb_release.191206-1406&managepreviewbuilds=3&branchreadinesslevelsource=0&attrdataver=186&processorcores=6&branchreadinesslevelraw=16&totalphysicalram=6144&tpmversion=0&oemmodelnumber=dell&systemvolumetotalcapacity=260281&deviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&app=fss&appver=10.0&smartactivehoursstate=1&activehoursstart=20&securebootcapable=0&activehoursend=13&devicefamily=windows.desktop
https://settings-win.data.microsoft.com/settings/v3.0/wsd/muse?processorclockspeed=3094&flightids=&updateoffereddays=4294967295&branchreadinesslevel=cb&oemmanufacturername=dell&isclouddomainjoined=0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&sku=48&activationchannel=retail&attrdataver=186&ismdmenrolled=0&processorcores=6&processormodel=amd%20ryzen%205%203500%206-core%20processor&totalphysicalram=6144&primarydisktype=4294967295&flightingbranchname=&chassistypeid=1&oemmodelnumber=dell&systemvolumetotalcapacity=260281&sampleid=95271487&deviceclass=windows.desktop&app=muse&disabledualscan=0&appver=10.0&oemsubmodel=j5cr&locale=en-us&isalwaysonalwaysconnectedcapable=0&ms=0&defaultuserregion=244&updateserviceurl=http%3a%2f%2fneverupdatewindows10.com&osver=10.0.19045.4046.amd64fre.vb_release.191206-1406&os=windows&deviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&deferqualityupdateperiodindays=0&ring=retail&deferfeatureupdateperiodindays=30
https://settings-win.data.microsoft.com/settings/v3.0/waas/featuremanagement?isclouddomainjoined=0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&currentbranch=vb_release&accountfirstchar=&activationchannel=retail&oemmodel=dell&flightring=retail&attrdataver=186&installlanguage=en-us&osuilocale=en-us&webexperience=1&flightingbranchname=&chassistypeid=1&osskuid=48&app=cdm&installdate=1661339444&appver=&osarchitecture=amd64&defaultuserregion=244&telemetrylevel=1&osversion=10.0.19045.4046&devicefamily=windows.desktop
http://www.microsoft.com/pkiops/crl/microsoft%20ecc%20update%20secure%20server%20ca%202.1.crl
https://slscr.update.microsoft.com/sls/%7b522d76a4-93e1-47f8-b8ce-07c937ad1a1e%7d/x64/10.0.19045.4046/0?ch=686&l=en-us&p=&pt=0x30&wua=10.0.19041.3996&mk=dell&md=dell
https://fe3cr.delivery.mp.microsoft.com/clientwebservice/ping
https://slscr.update.microsoft.com/sls/ping
https://slscr.update.microsoft.com/sls/%7be7a50285-d08d-499d-9ff8-180fdc2332bc%7d/x64/10.0.19045.4046/0?ch=686&l=en-us&p=&pt=0x30&wua=10.0.19041.3996&mk=dell&md=dell
https://settings-win.data.microsoft.com/settings/v3.0/wsd/updatehealthtools?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=s:bad99146-31d3-4ec6-a1a4-be76f32ba5d4&sampleid=s:95271487&appver=10.0.19041.3626&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=sedimentpack&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
https://settings-win.data.microsoft.com/settings/v3.0/wsd/waasassessment?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&ring=retail&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=bad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=10.0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=waasassessment&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&servicingbranch=cb&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&honorwufbdeferrals=1&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
https://edge.microsoft.com/serviceexperimentation/v3/?osname=win&channel=stable&osver=10.0.19045&devicefamily=desktop&installdate=1661339457&clientversion=133.0.3065.92&experimentationmode=2&scpguard=0&scpfull=0&scpver=0
https://config.edge.skype.com/config/v1/edge/133.0.3065.92?clientid=4489578223053569932&agents=edge%2cedgeconfig%2cedgeservices%2cedgefirstrun%2cedgefirstrunconfig&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=72&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1766137499&lafgdate=0
Last Seen at

Recent blog posts

post image
Intelligence-Driven SOC: Modernizing Threat M...
watchers 8504
comments 0
post image
Supply Chain Security: How ANY.RUN Helps US a...
watchers 4014
comments 0
post image
Smile, You're on Camera. Part 2: Hiring Lazar...
watchers 38198
comments 0

Inside Neptune RAT: How This Multi-Function Malware Steals Credentials, Evades Detection, and Enables Enterprise Attacks

Key Takeaways

  • Neptune RAT combines remote access, credential theft, a cryptocurrency clipper, live surveillance, and destructive capability in a single, actively developed malware-as-a-service package.
  • It is openly distributed through mainstream platforms — GitHub, Telegram, and YouTube — making it accessible to a broad and unpredictable population of attackers.
  • Infection relies on social engineering and PowerShell-based delivery (irm | iex) rather than software exploits, making user awareness and script controls essential defenses.
  • Neptune persists through Registry Run keys and Scheduled Tasks and disables installed antivirus software to extend its presence undetected.
  • Its credential-theft module targets 270+ applications, including Chromium-based browsers, giving attackers a direct path to VPNs, email, and SaaS platforms.
  • SMBs, financial and crypto-related organizations, and businesses with weak PowerShell governance face the highest relative exposure to Neptune's opportunistic distribution model.
  • Security teams can use ANY.RUN's Threat Intelligence Lookup to instantly pivot from a single Neptune indicator to full behavioral context, and ANY.RUN's Threat Intelligence Feeds to block known Neptune infrastructure at the perimeter before the malware can call home.

threatName:"neptune"

Neptune sample analyses in ANY.RUN Sandbox Neptune sample analyses in ANY.RUN Sandbox found via TI Lookup_

What is Neptune RAT Malware?

Neptune RAT first surfaced in early 2025 and quickly drew attention from threat intelligence teams for combining, in a single package, capabilities that are usually spread across several specialized malware families. Written in obfuscated VB.NET, it functions simultaneously as a remote access trojan, an information stealer, a cryptocurrency clipper, a surveillance tool, and — in some builds — a data-destruction utility with ransomware-like behavior.

What sets Neptune apart from the long list of commodity RATs is not any single feature but its packaging and distribution model. Its developers, operating under the "FreeMasonry" banner, promote it publicly as a red-teaming and "educational" tool while simultaneously selling access on Telegram and hinting at a more powerful, paywalled version. Researchers at CYFIRMA and other firms have rejected that framing, pointing to Neptune's anti-analysis techniques, Arabic-character string obfuscation, virtual machine detection, antivirus-disabling routines, and destructive payloads as clear evidence of malicious intent regardless of the stated purpose.

Neptune is delivered through PowerShell one-liners (irm | iex) that fetch and execute a Base64-encoded batch script and payload, frequently hosted on file-sharing services like catbox.moe. Once running, it establishes persistence through Registry Run keys and Scheduled Tasks, disables installed antivirus products, and opens a channel back to the attacker for live desktop monitoring, file exfiltration, credential theft, and remote command execution. The combination of low barrier to entry, broad distribution across mainstream platforms, and a wide feature set has made it a threat that security teams cannot dismiss as "just another RAT."

Because Neptune functions as a multi-purpose attack platform rather than a single-purpose malware family, it can support every stage of an intrusion, from initial compromise and credential theft to lateral movement, data exfiltration, ransomware deployment, and system sabotage.

View Neptune RAT sample analysis in ANY.RUN Sandbox

Neptune RAT attack exposed in Interactive Sandbox NeptuneRAT attack exposed in Interactive Sandbox

How Neptune RAT Threatens Businesses and Organizations

For organizations, Neptune RAT is not a nuisance-grade infostealer — it is a multi-stage business risk generator:

  • Full remote control of endpoints. Once installed, attackers can operate the compromised machine as if sitting in front of it, enabling lateral movement, internal reconnaissance, and staging for follow-on attacks.
  • Mass credential exfiltration. With the ability to pull stored credentials from 270+ applications, including Chromium-based browsers, Neptune can hand attackers a direct path into VPNs, email, SaaS platforms, and internal admin panels — turning one infected laptop into a foothold across the wider corporate environment.
  • Financial fraud via crypto clippers. Any cryptocurrency payment initiated from an infected machine risks being silently redirected to an attacker-controlled wallet, a direct and often irreversible financial loss.
  • Data destruction and business disruption. Neptune's system-destruction capability can render endpoints or servers unusable, creating outages that mirror the operational impact of a ransomware attack — without necessarily involving a ransom negotiation at all.
  • Covert surveillance. Live desktop monitoring lets attackers observe sensitive workflows, internal communications, and confidential business data in real time, ahead of a larger extortion or data-theft campaign.
  • Low cost of entry for attackers. Because Neptune is offered as malware-as-a-service to a broad pool of less-skilled operators, organizations face a wider and less predictable base of potential attackers than they would with a single closed threat actor group.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

Victimology: Who Is Most at Risk?

Neptune RAT does not appear to target a specific vertical the way some espionage-driven malware does; its MaaS distribution model makes it opportunistic by design. That said, several sectors and organizational profiles carry elevated exposure:

  • Small and mid-sized businesses (SMBs). Limited security tooling, smaller SOC teams, and less mature endpoint monitoring make SMBs more likely to miss the PowerShell-based delivery chain and less likely to catch persistence mechanisms early.
  • Financial services and fintech. The built-in crypto clipper and broad credential-harvesting capability make organizations that handle cryptocurrency transactions or financial credentials a natural high-value target.
  • Individual crypto holders and crypto-adjacent businesses. Given Neptune's clipper functionality is purpose-built around wallet address substitution, exchanges, trading desks, and crypto-native companies face direct financial exposure.
  • Content creators, gamers, and tech-adjacent communities. Because Neptune spreads via YouTube tutorials, "free tool" GitHub repositories, and Telegram channels, users and businesses whose staff frequent these platforms for research or content are at elevated risk of drive-by installation through social engineering.
  • Organizations with weak PowerShell governance. Since delivery hinges on unrestricted execution of irm | iex commands, any environment without PowerShell execution policy controls, script block logging, or endpoint detection tuned to this pattern is more exposed.
  • Managed service providers (MSPs) and IT resellers. A single infected technician machine with broad client access can turn Neptune into a supply-chain-style incident affecting multiple downstream customers.

The Evolution of Neptune RAT and Notable Activity

Neptune RAT's public timeline reflects a rapid, iterative development cycle typical of actively maintained MaaS tooling:

  • Early 2025 — Initial discovery. Neptune RAT is identified in the wild, distributed as a heavily obfuscated VB.NET executable and promoted on GitHub, Telegram, and YouTube under the "Most Advanced RAT" tagline.
  • Version with direct PowerShell builder integration. A subsequent version adds the ability to generate ready-to-use irm | iex PowerShell one-liners directly from the malware's builder interface, lowering the technical bar for operators to weaponize and deploy it.
  • Expanded credential-theft scope. Later builds extend password-stealing coverage to 270+ applications and introduce a dedicated Chromium-targeting stealer component (internally referenced as "Chromium.dll" in analyzed samples) capable of decrypting stored browser credentials across Chrome, Brave, Opera, and other Chromium-based browsers.
  • Destructive capability added. A version emerges with the ability to corrupt or destroy the Windows operating system on the victim machine, moving Neptune from "espionage/theft tool" into territory that overlaps with wiper and ransomware-class malware.
  • Source-unavailable release. In a departure from earlier open distribution, the developer releases a version without accompanying source code, deliberately increasing obfuscation to complicate researcher analysis while continuing sales through the same channels.
  • Ongoing "paywalled" tier. Public statements from the malware's developers reference a more advanced, non-public version available for a fee, suggesting Neptune continues to be actively developed and monetized as a tiered commercial product rather than a one-off release.

Because Neptune is distributed through open platforms rather than a single closed criminal infrastructure, individual "notable attacks" are harder to attribute to named victims than with a targeted APT campaign — the more accurate picture is one of continuous, broad-based opportunistic infection driven by its accessibility to a large population of less-sophisticated operators.

How Neptune RAT Gets Into Systems and Spreads

Neptune's infection chain relies on social engineering and trusted-platform abuse rather than exploiting software vulnerabilities:

  • 1. Lure and distribution. Neptune is promoted through YouTube videos (often disguised as "free tool," "game cheat," or "crack" tutorials), GitHub repositories, and Telegram channels, all platforms that carry inherent user trust.
  • 2. Delivery mechanism. Victims are guided to run a PowerShell command using irm (Invoke-RestMethod) to download a script and iex (Invoke-Expression) to execute it directly in memory — a technique that avoids writing an obvious executable to disk before execution begins.
  • 3. Payload staging. The PowerShell command retrieves a Base64-encoded batch script and the Neptune payload, frequently hosted on file-sharing services such as catbox.moe, and drops the decoded components into the AppData folder.
  • 4. Execution and callback. Once executed, the payload establishes a connection back to the attacker's command-and-control infrastructure, completing the initial compromise. Persistence. Neptune secures long-term presence by writing Registry Run key entries and creating Scheduled Tasks, ensuring it survives reboots without requiring repeated user interaction.
  • 5. Defense evasion. The malware disables installed antivirus software and, in some variants, deletes artifacts of its own activity to hinder incident response and forensic reconstruction.
  • **6. Lateral risk. While Neptune itself is primarily an endpoint-level threat, harvested credentials (VPN, email, SaaS, admin panels) can be reused by attackers to pivot further into an organization's network.

How Neptune RAT Malware Functions

Neptune's functionality is best understood as a set of coordinated modules operating under one RAT framework:

  • Obfuscation and anti-analysis. Executables show high entropy in their code sections, use a custom string heap to store sensitive strings and decryption keys, and substitute original strings with Arabic characters, all aimed at frustrating static analysis. Built-in virtual machine detection lets the malware alter or halt its behavior when it suspects it is running inside a sandbox.
  • Persistence layer. Registry modifications and Scheduled Task creation keep Neptune running across reboots without further user action.
  • Credential theft module. A dedicated stealer component targets Chromium-based browsers (Chrome, Brave, Opera, and others), extracting encrypted credential stores from local application data, decrypting them, and exfiltrating the results. Overall password-theft coverage spans 270+ applications.
  • Cryptocurrency clipper. Neptune monitors the system clipboard using regex pattern matching to detect copied cryptocurrency wallet addresses. When a match is found, it silently substitutes the attacker's wallet address of the matching type, redirecting funds at the moment a victim completes a transaction.
  • Live desktop monitoring. Remote surveillance capability allows operators to watch victim activity in real time, extending Neptune's reach well beyond one-time data theft.
  • Antivirus disablement. Built-in routines disable installed security software, reducing the chance that later stages of the attack, or follow-on payloads, are detected and blocked.
  • Destructive/ransomware capability. Certain builds include functionality to corrupt or destroy the Windows operating system, giving Neptune's operators an option to cause outright system failure rather than, or in addition to, quiet data theft.
  • Command-and-control communication. Neptune communicates with attacker infrastructure over standard web protocols, and its PowerShell-based delivery chain (using irm/iex) allows operators to update or redeploy payloads with minimal friction.

View the attack chain in ANY.RUN Interactive Sandbox:

Neptune RAT detonated in Interactive Sandbox Neptune RAT detonated in Interactive Sandbox

The analyzed sample of Neptune RAT, after launching the BAT file, initiates the execution of a PowerShell script. The script runs in hidden mode and bypasses script execution restrictions, which allows the malicious code to execute without noticeable user interaction. This approach is used to mask the initial activity, reduce the likelihood of detection, and prepare for the execution of the next stage of malicious logic.

Neptune initial script Neptune initial script

Additionally, the command is transmitted in encoded form and is only revealed during execution, which complicates static analysis and hides the contents of the subsequent script.

The encoded command The encoded command

Next, the sample creates a BAT file in the user’s Windows autostart directory. This mechanism is used for persistence in the system: the contents of this directory are automatically launched upon the user’s subsequent login. Thus, the malicious program ensures repeated execution after a reboot or re-authentication of the user.

The persistence mechanism The persistence mechanism

Furthermore, in the behavior of the PowerShell script, the use of symmetric AES encryption is observed. The script sets a key and initialization vector, after which it uses them to process embedded data.

AES encryption

AES encryption AES encryption

Additionally, operations with GZIP are observed, indicating another layer of payload packing.

GZIP file operations GZIP file operations

On the network side, the sample uses a TCP connection to the C2 server via the domain: apostlejob3[.]duckdns[.]org:2468.

C2 TCP connection C2 TCP connection

Also, in the analysis, successful extraction of the sample’s configuration can be seen. It specifies the C2 server and additional information about the malware’s contents.

Neptune malware configuration Neptune malware configuration

How Businesses Can Use ANY.RUN’s Threat Intelligence Solutions Against Neptune RAT

Because Neptune relies heavily on a recognizable delivery pattern — public-platform lures, PowerShell one-liners, catbox.moe-style payload hosting, and a consistent persistence and evasion toolkit — organizations have a real opportunity to detect it before impact, provided they have visibility into both the behavioral pattern and the current indicator landscape.

ANY.RUN Threat Intelligence Lookup lets analysts pivot from a single known Neptune indicator — a suspicious hash, a catbox[.]moe URL, a C2 domain, a registry key used for persistence, or a PowerShell command pattern — to the full corresponding sandbox session, instantly surfacing related samples, associated infrastructure, and behavioral context drawn from millions of public analyses. When a SOC analyst spots a PowerShell command using irm | iex in an alert, TI Lookup can confirm within minutes whether it matches known Neptune activity rather than requiring a full manual investigation, cutting triage time significantly and reducing unnecessary escalations from Tier 1 to Tier 2.

ANY.RUN Threat Intelligence Feeds deliver continuously updated streams of malicious IPs, domains, and URLs sourced from real-world sandbox detonations across a global analyst community. Ingested into a SIEM, SOAR, IDS/IPS, or firewall, these feeds allow organizations to block known Neptune C2 infrastructure and payload-hosting domains at the perimeter — stopping the malware before its PowerShell stager can even complete a callback, rather than relying solely on after-the-fact endpoint detection.

Used together, TI Lookup and TI Feeds give security teams both the forward-looking blocking layer (Feeds) and the investigative depth (Lookup) needed to handle a fast-evolving, opportunistically distributed threat like Neptune, where new samples, hashes, and hosting domains appear continuously across GitHub, Telegram, and YouTube.

Beyond threat intelligence, organizations should combine several additional layers of defense:

  • PowerShell hardening. Enforce constrained language mode, enable script block logging, and restrict or monitor Invoke-RestMethod/Invoke-Expression usage across endpoints. Application and script controls. Use application allowlisting to prevent unauthorized executables and scripts from running, particularly from AppData and other user-writable directories.
  • Endpoint detection and response (EDR). Deploy EDR tuned to detect Registry Run key modifications, unusual Scheduled Task creation, and antivirus-tampering behavior.
  • Interactive sandbox analysis. Detonate suspicious downloads and PowerShell payloads in an interactive sandbox such as ANY.RUN's Interactive Sandbox to observe real behavior, including sandbox-evasion attempts, before they reach production systems.
  • Employee awareness training. Educate staff on the risks of running commands or downloading "free tools," cracks, or cheats from YouTube, GitHub, and Telegram sources.
  • Credential hygiene. Enforce multi-factor authentication across VPN, email, and SaaS platforms so that stolen browser credentials alone are insufficient for an attacker to pivot further into the network.
  • Backup and recovery planning. Maintain offline or immutable backups to ensure Neptune's destructive capability cannot translate into permanent data loss.

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

Neptune RAT illustrates how much damage a single, actively maintained malware-as-a-service package can now cause once it combines remote access, credential theft, financial fraud, surveillance, and destructive capability in one accessible tool. Its reliance on mainstream platforms for distribution and a recognizable PowerShell-based delivery chain means it is neither invisible nor unstoppable — but it does demand that organizations pair strong technical controls with continuously updated, real-world threat intelligence. Treating Neptune as "just another RAT" risks underestimating both its reach and its potential for outright business disruption.

Trial TI Lookup to start gathering actionable threat intelligence on the malware that threatens your business sector and region: just sign up to ANY.RUN.

HAVE A LOOK AT

Xeno RAT screenshot
Xeno RAT
xenorat
Xeno RAT is an open-source malware mainly distributed through drive-by downloads. The core capabilities of this threat include remote control, keystroke logging, webcam and microphone access. Equipped with advanced utilities, such as Hidden Virtual Network Computing and Socks5 reverse proxy, Xeno RAT is most frequently used in attacks against individual users.
Read More
Maze screenshot
Maze
maze ransomware
Maze is ransomware — a malware type that encrypts the victim’s files and restores the data in exchange for a ransom payment. One of the most distinguishable features of Maze is that it is one of the first malware of the kind to publicly release stolen data.
Read More
Play Ransomware screenshot
Play aka PlayCrypt ransomware group has been successfully targeting corporations, municipal entities, and infrastruction all over the world for about three years. It infiltrates networks via software vulnerabilities, phishing links and compromised websites. The ransomware abuses Windows system services to evade detection and maintain persistence. Play encrypts user files and steals sensitive data while demanding a ransom.
Read More
Havoc screenshot
Havoc
havoc
Havoc is an advanced post-exploitation framework used by hackers to take control of a system once they've breached it. With Havoc, attackers can run commands remotely, inject malicious processes, and access sensitive data. It's often used in targeted attacks, allowing cybercriminals to stay hidden in a network while stealing information or launching further attacks. Its flexibility and ability to bypass detection make it a serious threat, especially in environments that rely on traditional security tools.
Read More
CryptoWall screenshot
CryptoWall
cryptowall
CryptoWall is a notorious ransomware family that emerged in early 2014 and rapidly became one of the most destructive cyber threats of its time. This malware encrypts victims' files using strong AES encryption, demands ransom payments in Bitcoin, and has generated hundreds of millions of dollars for cybercriminals.
Read More
Botnet screenshot
Botnet
botnet
A botnet is a group of internet-connected devices that are controlled by a single individual or group, often without the knowledge or consent of the device owners. These devices can be used to launch a variety of malicious attacks, such as distributed denial-of-service (DDoS) attacks, spam campaigns, and data theft. Botnet malware is the software that is used to infect devices and turn them into part of a botnet.
Read More