Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

RatonRAT

46
Global rank
74
Month rank
87 infographic chevron week
Week rank

RatonRAT is a .NET-based Remote Access Trojan targeting Windows systems. It supports credential theft, screen capture, system and hardware discovery, persistence, and C2 communication. Samples use techniques such as Registry Run keys and scheduled tasks for persistence, with some variants employing anti-analysis and evasion techniques.

RAT
Type
Unknown
Origin
1 March, 2026
First seen
8 October, 2026
Last seen

How to analyze RatonRAT with ANY.RUN

RAT
Type
Unknown
Origin
1 March, 2026
First seen
8 October, 2026
Last seen

IOCs

IP addresses
150.171.109.104
150.171.27.11
193.161.193.99
151.80.20.29
48.209.6.48
2.16.204.143
150.171.109.98
51.159.98.203
48.192.1.65
150.171.28.11
135.233.95.144
150.171.22.17
23.11.41.157
104.18.22.222
172.211.123.249
94.139.32.25
135.233.95.135
20.190.159.2
142.251.14.132
150.171.109.99
Hashes
accccfbe45d9f08ffeed9916e37b33e98c65be012cfff6e7fa7b67210ce1fefb
6a437098dcbb8a0354ae28a5f7825685f471c13cecb83186cc950844df7c76c4
966a474060a8aca70c73ba09d0b6fe2353035961c7107b9003ef879c010ff8da
bf3fb84664f4097f1a8a9bc71a51dcf8cf1a905d4080a4d290da1730866e856f
c3ae599b5218516915f6542779ef577d5ad5de3d84a116e671c09e15e4591285
aced52254a8c3cb6ad30f99f8b745296926c49373cab00824c2c4c10ad325b10
bafa6ed04ca2782270074127a0498dde022c2a9f4096c6bb2b8e3c08bb3d404d
ad72490f67c7bfad125582454e536b0a8bce9dc4cb0fb3ea1bd994525b5a6b0c
0cf098dfe5bbb46fc0132b3cf0c54b06b4d2c8390d847ee2a65d20f9b7480f4c
9b32c491d0bfebdca1455f73c3c6f71796d433a39818c06c353da588de650f81
2824cf97513dc3ecc261f378bfd595ae95a5997e9d1c63f5731a58b1f8cd54f9
64e01bc292ba2ea1699576fcc445367047520ee895e290ccee20c24c9336d8ef
2445cad863be47bb1c15b57a4960b7b0d01864e63cdfde6395f3b2689dc1444b
ff702ca753a7e3b75f9d9850cc9343e28e8d60f8005a2c955c8ac2105532b2c9
af889c1deb6f9248961c2f8ba4307a8206d7163616a5b7455d17cead00068317
728d8cbd71263680a4e41399db65b3f2b8175d50ca630afd30643ced9ffe831f
22bc37b47ce8a832f39701641dc358357676e9be187a93a4c5d4b016e29238ae
cc3e9077fcc9bd0dfc5dd3924c6c48b8345f32cee24fccc508c279f45b2abe61
14895bf43ce9b76c0ff4f9aef93dbe8bb6ca496894870cf0c007b189e0cef00e
7ccc7b17bfe01c3c7dd33eff8f80d0b57fc9b175815e766c9c1c1e893725e20f
Domains
gofile.io
crl.microsoft.com
edge.microsoft.com
s.gofile.io
api.gofile.io
update.googleapis.com
slscr.update.microsoft.com
config.edge.skype.com
api.edgeoffer.microsoft.com
activation-v2.sls.microsoft.com
cold-na-phx-6.gofile.io
google.com
clients2.googleusercontent.com
www.bing.com
fe3cr.delivery.mp.microsoft.com
edge-consumer-static.azureedge.net
xpaywalletcdn.azureedge.net
self.events.data.microsoft.com
login.live.com
copilot.microsoft.com
URLs
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceaz1vqyrvgl0erhqlcpm8gy%3d
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbtrjrydryt%2bapf3gspypfhbxr5xtqqus9tippmhxdiunkhmewnpyim8s8yceajtxtab8my1oj8mfwpz%2f7y%3d
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://oneocsp.microsoft.com/ocsp/mfqwujbqme4wtdajbgurdgmcgguabbq3l3%2f%2fa6adk8nray2gxzvayrhg4aqub6t%2b2v%2bxq3lso2d33ojhnyhhqoucezmaaaafuwohyjguzpcaaaaaaau%3d
http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:xyuvfkogzye8qhjcd8wfoswrk3xt4mfuiiedpawzama&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
https://settings-win.data.microsoft.com/settings/v3.0/wsd/waasassessment?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&ring=retail&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=bad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=10.0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=waasassessment&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&servicingbranch=cb&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&honorwufbdeferrals=1&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
https://gofile.io/d/uqtsuasd
https://gofile.io/assets/fonts/inter-latin-wght-normal.woff2
https://gofile.io/assets/css/app.css
https://gofile.io/js/app.js
https://gofile.io/js/wt.obf.js
https://gofile.io/assets/vendor/lucide.min.js
https://gofile.io/js/core/dom.js
https://gofile.io/js/core/analytics.js
https://gofile.io/js/core/router.js
https://gofile.io/js/core/navigation.js
https://gofile.io/js/layout/shell.js
https://gofile.io/js/accounts/accountservice.js
https://gofile.io/js/pages/index.js
https://gofile.io/js/pages/home.js
Last Seen at

Recent blog posts

post image
Making Threat Intelligence Work for SOC Teams...
watchers 1389
comments 0
post image
5 Critical Pain Points of Modern US SOCs and...
watchers 3845
comments 0
post image
IronChain Ransomware Threatens Businesses wit...
watchers 5997
comments 0

Key Takeaways

  • Credential and Data Theft: RatonRAT can steal credentials and collect system and hardware information from compromised Windows systems.
  • Persistence Mechanisms: The malware uses scheduled tasks and Active Setup to maintain execution after user logon.
  • Defense Evasion: RatonRAT can bypass PowerShell ExecutionPolicy and add its process to Microsoft Defender exclusions.
  • System and VM Discovery: It checks running processes, privileges, BIOS and disk information, as well as VirtualBox and VMware environments.
  • C2 Communication: After establishing itself, RatonRAT connects to a configured command-and-control server to receive further instructions.
  • Configurable .NET Malware: The family uses a configurable .NET architecture and Costura/Fody to bundle its components.
  • ANY.RUN’s Interactive Sandbox analysis reveals a sequence involving self-relocation, BAT-based execution, persistence, Defender exclusion, virtual environment checks, and subsequent C2 communication.

RatonRAT detonated inside ANY.RUN’s Interactive Sandbox

RatonRAT detonated inside ANY.RUN’s Interactive Sandbox

What is RatonRAT?

RatonRAT is a .NET-based Remote Access Trojan targeting Windows systems. The malware provides attackers with remote access to compromised hosts and supports capabilities including credential theft, system information collection, persistence, and security evasion.

The family is characterized by its configurable architecture and the use of Costura/Fody to package .NET components. This allows different samples to maintain a similar underlying structure while using customized configurations.

Observed samples also demonstrate a focus on maintaining access and reducing visibility after execution. The malware can relocate itself to an application-data directory, establish automatic startup mechanisms, modify Microsoft Defender exclusions, and communicate with a configured C2 server.

How RatonRAT Impacts Businesses and Organizations

A RatonRAT infection can create several risks for businesses and organizations:

  • Credential exposure: The malware can collect credentials from compromised systems, potentially exposing access to corporate services and applications.
  • Unauthorized remote access: As a RAT, RatonRAT provides attackers with a channel for remote control and further interaction with an infected endpoint.
  • Persistence: Scheduled tasks and Active Setup entries can allow the malware to restart automatically after user logon or environment initialization.
  • Security control bypass: Changes to Microsoft Defender exclusions can reduce endpoint protection visibility and allow the malware to continue operating.
  • Reconnaissance: System, hardware, process, disk, BIOS, and privilege information can help attackers understand the compromised environment.
  • Virtualization awareness: Checks for VirtualBox and VMware can allow the malware to identify analysis or virtualized environments.
  • Follow-on activity: Once a C2 connection is established, additional behavior depends on the commands received by the infected client.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

Victimology: Who Can Be Affected?

RatonRAT targets Windows systems, making organizations that rely on Windows workstations and endpoints potentially exposed to the malware.

Its capabilities are not limited to a particular industry. Credential collection, system reconnaissance, persistence, and remote access are broadly applicable to attacks against corporate endpoints.

Because RatonRAT can receive instructions from a configured C2 server, the activity performed after infection may vary between samples and campaigns.

How Does RatonRAT Function?

Observing a RatonRAT sample inside ANY.RUN’s Interactive Sandbox shows a sequence focused on establishing a stable execution location, creating persistence, weakening endpoint protections, collecting information about the environment, and contacting the C2 server.

The general execution flow begins with the initial executable relocating itself, followed by BAT-based execution, persistence, security evasion, system reconnaissance, and C2 communication.

RatonRAT analysis in ANY.RUN’s Interactive Sandbox

RatonRAT analysis in ANY.RUN’s Interactive Sandbox

Stage 1: Self-Relocation and BAT Creation

Immediately after execution, an observed RatonRAT sample copies itself into: %APPDATA%\Roaming\PlatformRuntime\

The malware also creates a BAT file inside: %APPDATA%\Roaming\Temp\

The BAT filename frequently follows a pattern similar to: cleanup_[a-z0-9]{30}.bat

The exact filename and script contents can vary between samples, but the overall structure remains similar.

The BAT script uses helper commands through cmd.exe and timeout.exe. It launches the relocated executable and attempts to remove the original executable from the desktop, helping the malware continue execution from its new location while cleaning up traces of the initial file.

RatonRAT creating a BAT launcher and relocating itself

RatonRAT creating a BAT launcher and relocating itself

Stage 2: BAT-Based Execution

The newly created BAT file is subsequently executed. Its primary purpose is to start the copied RatonRAT executable from the %APPDATA%\Roaming\PlatformRuntime\ directory.

The script also performs cleanup operations intended to remove traces of the original executable.

This creates an execution sequence in which the initial file is no longer the main execution location:

Original executable → BAT script → relocated RatonRAT copy

Stage 3: Establishing Persistence

After launching from its new location, RatonRAT proceeds to establish persistence.

One observed mechanism is a scheduled task configured to launch the malicious executable when the user logs in. The task can be created with elevated privileges, allowing the malware to regain execution automatically after login.

RatonRAT creating a scheduled task for persistence

RatonRAT creating a scheduled task for persistence

Some samples use a different persistence mechanism based on Active Setup rather than a scheduled task. Active Setup allows a component to execute automatically when the user's environment is initialized.

This variation demonstrates that persistence behavior can differ between RatonRAT samples while serving the same purpose: maintaining execution after the initial compromise.

RatonRAT using Active Setup to establish persistence

RatonRAT using Active Setup to establish persistence

Stage 4: PowerShell and Microsoft Defender Evasion

After persistence is established, RatonRAT launches PowerShell with an ExecutionPolicy bypass.

The malware also attempts to add its process to Microsoft Defender exclusions. This can reduce the ability of the endpoint security product to inspect or block the malicious process.

RatonRAT bypassing PowerShell ExecutionPolicy

RatonRAT bypassing PowerShell ExecutionPolicy

The combination of PowerShell execution and security-control modification represents an important behavioral signal for defenders investigating suspicious activity on Windows endpoints.

RatonRAT modifying Microsoft Defender exclusions

RatonRAT modifying Microsoft Defender exclusions

Stage 5: System and Virtual Environment Discovery

RatonRAT then collects information about the environment in which it is running.

Observed checks include:

  • VirtualBox indicators
  • VMware indicators
  • BIOS information
  • Disk information
  • Running processes
  • Available privileges
  • System and hardware characteristics

The virtualization checks can help the malware determine whether it is operating inside a virtualized or potentially analyzed environment.

RatonRAT checking for virtualization and system information

RatonRAT checking for virtualization and system information

Stage 6: Mutex Creation

Another characteristic observed during execution is the creation of randomly generated mutexes.

These mutex names vary between executions and samples, but their purpose is consistent with preventing multiple instances of the malware from running simultaneously or helping the malware coordinate its execution state.

RatonRAT creating a randomly generated mutex

RatonRAT creating a randomly generated mutex

Stage 7: C2 Communication

Once the malware is running from its intended directory, RatonRAT establishes network communication with its configured C2 server.

This connection provides the attacker with a channel for controlling the infected client and delivering further instructions.

RatonRAT communicating with its configured C2 server

RatonRAT communicating with its configured C2 server

The subsequent behavior depends on the commands received by the RatonRAT client. As a result, activity observed after the initial C2 connection can vary between infections.

RatonRAT Behavior at a Glance

The observed samples demonstrate several layers of activity designed to maintain execution and reduce the malware's visibility:

  • Relocation moves the executable from its original location into %APPDATA%\Roaming\PlatformRuntime.
  • BAT execution launches the relocated copy and attempts to remove the original file.
  • Persistence is established through scheduled tasks or Active Setup.
  • PowerShell is used with an ExecutionPolicy bypass.
  • Defender exclusions are modified to reduce security-tool interference.
  • Environment discovery collects system, hardware, process, privilege, and virtualization information.
  • Mutexes are created using randomized names.
  • C2 communication enables further remote instructions.

This combination gives RatonRAT multiple opportunities to survive execution, understand its environment, and maintain communication with its operator.

How Organizations Can Use ANY.RUN’s Threat Intelligence to Investigate RatonRAT

RatonRAT samples can vary in configuration, persistence mechanisms, filenames, and infrastructure. For this reason, relying exclusively on static indicators such as file hashes may provide limited visibility into related activity.

ANY.RUN’s Threat Intelligence can help analysts connect individual RatonRAT samples with related infrastructure, behavioral artifacts, and previous sandbox executions.

Threat Intelligence Lookup can be used to investigate known RatonRAT indicators and identify related artifacts.

threatName:"raton"

Searching for RatonRAT in ANY.RUN’s TI Lookup

Searching for RatonRAT in ANY.RUN’s TI Lookup

Identify Behavioral Indicators

Defenders investigating potential RatonRAT activity can monitor for combinations of behaviors such as:

  • Executables copying themselves into %APPDATA%\Roaming\PlatformRuntime\
  • BAT files created under %APPDATA%\Roaming\Temp\
  • BAT filenames matching cleanup_[a-z0-9]{30}.bat
  • cmd.exe and timeout.exe launched by suspicious scripts
  • Newly created scheduled tasks launching executables from user-writable directories
  • Active Setup entries associated with unexpected executables
  • PowerShell launched with an ExecutionPolicy bypass
  • Unexpected modifications to Microsoft Defender exclusions
  • VirtualBox or VMware environment checks by suspicious processes
  • Unusual BIOS, disk, process, or privilege discovery
  • Randomly generated mutex creation
  • Unexpected outbound connections to configured C2 infrastructure

Behavioral detection can be particularly useful because individual RatonRAT samples may use different filenames, configurations, or persistence mechanisms.

Powered by data contributed by 16,000 organizations and 700,000 security professionals, fresh ANY.RUN’s Threat Intelligence Feeds provide SOC teams with current indicators linked to RatonRAT activity. Feeds can be integrated with SIEM, SOAR, and EDR platforms, and other security solutions to help analysts detect suspicious infrastructure, investigate related activity, and track changes in the threat landscape.

Threat intelligence from 16K SOCs and 700K analysts

Threat intelligence from 16K SOCs and 700K analysts

Analysts can use ANY RUN’s Threat Intelligence Lookup to pivot from a suspicious sample or indicator toward related activity.

For example, an investigation can begin with a suspicious executable and expand to:

  • Related RatonRAT samples
  • Shared hashes and artifacts
  • C2 infrastructure
  • Similar BAT launchers
  • Persistence mechanisms
  • PowerShell activity
  • Common configuration characteristics
  • Previous sandbox executions

This approach can help analysts determine whether an isolated endpoint event is connected to broader RatonRAT activity.

Respond to a RatonRAT Infection

If RatonRAT is identified on a corporate endpoint, incident response should address both the compromised host and any credentials or sessions that may have been exposed.

Recommended actions include:

  • Isolate the affected endpoint.
  • Preserve relevant forensic evidence.
  • Remove unauthorized persistence mechanisms.
  • Reset credentials that may have been exposed.
  • Revoke active sessions where appropriate.
  • Review authentication logs for suspicious activity.
  • Investigate Microsoft Defender exclusion changes.
  • Search for related BAT files, scheduled tasks, Active Setup entries, and suspicious PowerShell activity.
  • Identify and block associated C2 infrastructure where appropriate.
  • Search other endpoints for matching behavioral indicators.

As RatonRAT can maintain persistence and communicate with a C2 server, removing the initial executable alone may not be sufficient to determine whether the system remains compromised.

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

RatonRAT demonstrates how a relatively compact Windows RAT can combine persistence, system reconnaissance, credential theft, defense evasion, and C2 communication into a single infection chain.

Observed samples relocate themselves, use BAT scripts for execution and cleanup, establish persistence through scheduled tasks or Active Setup, modify Microsoft Defender exclusions, inspect the host environment, and communicate with a configured C2 server.

For defenders, these behaviors provide multiple opportunities for detection. Monitoring persistence creation, suspicious PowerShell activity, Defender exclusion changes, user-writable execution paths, virtualization checks, and unexpected C2 communication can help identify RatonRAT activity beyond simple hash-based detection.

Frequently Asked Questions: RatonRAT

1. What is RatonRAT?

RatonRAT is a .NET-based Remote Access Trojan targeting Windows systems. It supports capabilities including credential theft, system information collection, persistence, security evasion, and remote communication with a C2 server.

2. What can RatonRAT do?

RatonRAT can collect credentials and system information, establish persistence, inspect the host environment, evade certain security controls, and communicate with an attacker-controlled C2 server for further instructions.

3. How does RatonRAT establish persistence?

Observed samples can create a scheduled task that launches the malware at user logon. Some variants instead use an Active Setup entry to automatically execute a component during user-environment initialization.

4. How can RatonRAT evade detection?

RatonRAT can launch PowerShell with an ExecutionPolicy bypass and add its process to Microsoft Defender exclusions. It also checks for virtualized environments and uses self-relocation and cleanup scripts to reduce traces of its initial execution.

5. What does RatonRAT check on an infected system?

Observed samples inspect BIOS and disk information, running processes, system and hardware characteristics, available privileges, and virtualization indicators associated with VirtualBox and VMware.

6. How can interactive sandboxing and threat intelligence help investigate RatonRAT?

Interactive sandboxing allows analysts to observe the malware's behavior in a controlled environment, including self-relocation, BAT execution, persistence creation, PowerShell activity, Defender exclusion changes, environment discovery, mutex creation, and C2 communication.

Threat intelligence can then be used to pivot from observed indicators to related samples and infrastructure.

HAVE A LOOK AT

OnyxC2 screenshot
OnyxC2
onyxc2
OnyxC2 is a sophisticated Malware-as-a-Service platform sold on cybercrime forums that provides a turnkey solution for high-volume credential theft. The malware targets over 200 applications, scraping sensitive data from browsers, cryptocurrency wallets, and business-critical tools like FTP and email clients. It employs advanced evasion techniques, such as DLL sideloading and browser fingerprinting, to deliver encrypted payloads through legitimate signed binaries.
Read More
Cobalt Strike screenshot
Cobalt Strike
cobaltstrike
Cobalt Strike is a legitimate penetration software toolkit developed by Forta. But its cracked versions are widely adopted by bad actors, who use it as a C2 system of choice for targeted attacks.
Read More
Neptune RAT screenshot
Neptune RAT is a Visual Basic .NET remote access trojan that gives attackers full control over infected Windows machines while stealing credentials from 270+ applications, hijacking cryptocurrency transactions, spying on victims in real time, and, in its most destructive mode, wiping the operating system entirely. Marketed openly on GitHub, Telegram, and YouTube as the "Most Advanced RAT," it is distributed under a malware-as-a-service model.
Read More
Phobos screenshot
Phobos
phobos ransomware
Phobos is a ransomware that locks or encrypts files to demand a ransom. It uses AES encryption with different extensions, which leaves no chance to recover the infected files.
Read More
Godfather screenshot
Godfather
godfather
The Godfather malware is an Android banking Trojan capable of bypassing MFA that targets mobile banking and cryptocurrency applications. Known for its ability to evade detection and mimic legitimate software, it poses a significant threat to individuals and organizations by stealing sensitive data and enabling financial fraud.
Read More
TrustConnect screenshot
TrustConnect
trustconnect
TrustConnect is a MaaS platform that disguises a Remote Access Trojan (RAT) as a legitimate Remote Monitoring and Management (RMM) tool. The operators built an AI-generated business website, obtained a fraudulently acquired Extended Validation (EV) code-signing certificate, and created fake customer statistics and documentation to make TrustConnect appear to the world — and to security tools — as a legitimate software company.
Read More