Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

RatonRAT

46
Global rank
68 infographic chevron month
Month rank
63 infographic chevron week
Week rank

RatonRAT is a .NET-based Remote Access Trojan targeting Windows systems. It supports credential theft, screen capture, system and hardware discovery, persistence, and C2 communication. Samples use techniques such as Registry Run keys and scheduled tasks for persistence, with some variants employing anti-analysis and evasion techniques.

RAT
Type
Unknown
Origin
1 March, 2026
First seen
17 September, 2026
Last seen

How to analyze RatonRAT with ANY.RUN

RAT
Type
Unknown
Origin
1 March, 2026
First seen
17 September, 2026
Last seen

IOCs

IP addresses
20.165.94.63
23.11.41.157
94.156.250.190
23.52.181.141
2.16.164.66
2.23.246.101
23.216.77.11
40.126.31.0
48.209.138.189
48.209.138.168
23.209.213.129
185.199.111.153
128.24.231.64
20.190.159.73
104.18.20.213
185.199.111.133
57.153.246.3
2.16.241.203
135.233.95.135
95.100.102.101
Hashes
accccfbe45d9f08ffeed9916e37b33e98c65be012cfff6e7fa7b67210ce1fefb
966a474060a8aca70c73ba09d0b6fe2353035961c7107b9003ef879c010ff8da
bf3fb84664f4097f1a8a9bc71a51dcf8cf1a905d4080a4d290da1730866e856f
c3ae599b5218516915f6542779ef577d5ad5de3d84a116e671c09e15e4591285
aced52254a8c3cb6ad30f99f8b745296926c49373cab00824c2c4c10ad325b10
bafa6ed04ca2782270074127a0498dde022c2a9f4096c6bb2b8e3c08bb3d404d
af66d72417f654cb1c75fb6874d6694a9868257b3e1e31e8a2c1c4c39c736146
f0c07af0e84d4dd4da4bd7823ba4535bc0481b3bf623ed40b659b68147a6bb75
87e6b80f7e1dfd4c76fe0d5a0b4671265fc59bb4d25bfac08dea489927b58a87
b6c5f5b2e2499fceb92eba441e00e5137337c18a6b6eac9562661a11ca92aafc
a05e371abf96195770ac4f84653d987d63731fed528e98c7fe0d10ce66e37d7e
7796a9ec97a1ff29e682855839845da9fe26b6ddcc34addbb514cd73e7a9f02a
504dd507c34817a8a8be1965e82dd091ff0f5a85ba444ea784783f196677bfd1
82a92cb6b9001e013c653c65e4ae460346770ec7512856879e63018d9cafc41a
d8ee0fc96ce8de2e37bc8fdc051da7c1852b9a510270e663ba17281de23f049b
e8e80e5be65bad0efeac3366d823494e0b1676db039923a35cfb63496d3607d6
3dd5ea8a14eb665ba6057d424f94e5e83757ffaab456578dbf038af04053b19e
365b5625b2f6df20a723b90db5743d210cebef228b44e034949f9c43a907216d
489432a46f9f0155b1e8857bea0a2fbdbe4b2ce8ac9937a50ff1b8822759aaab
55a271a4091da00ffaa8130f84c642374e9c025a7bb0ef8a60a52ed93dbf14ce
Domains
fe3cr.delivery.mp.microsoft.com
2rjswlhmkq.localto.net
api.github.com
ocsp.digicert.com
slscr.update.microsoft.com
yr1.c.lencr.org
login.live.com
www.microsoft.com
ecs.office.com
yr.c.lencr.org
rufus.ie
crl.microsoft.com
settings-win.data.microsoft.com
ocsp.sectigo.com
go.microsoft.com
x1.c.lencr.org
self.events.data.microsoft.com
activation-v2.sls.microsoft.com
google.com
client.wns.windows.com
URLs
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/microsoft%20secure%20server%20ca%202026.crl
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceaz1vqyrvgl0erhqlcpm8gy%3d
http://x1.c.lencr.org/
http://yr.c.lencr.org/
https://rufus.ie/sbat_level.txt
https://rufus.ie/sb_active.txt
https://go.microsoft.com/fwlink/?linkid=2257403&clcid=0x409
http://yr1.c.lencr.org/106.crl
http://ocsp.usertrust.com/mfewtzbnmeswstajbgurdgmcgguabbsr83eyjy3njhjvpn5bepfc6mxawqquouejhttpgckwdnrjdtzgnczjy5ocebqer%2bxt6ogbxbkxqbankn0%3d
https://rufus.ie/sb_revoked.txt
https://rufus.ie/fido.ver
https://github.com/pbatard/fido/releases/download/v1.70/fido.ps1.lzma
http://ocsp.sectigo.com/mfiwudbomewwsjajbgurdgmcgguabbs3dhjwomgbojfu%2fpy58baob6amcwquf5mobmfv5c1wqaoqpqpt6rq4jmmceqclnr21lnudt%2fxalqewe5u8
http://yr1.c.lencr.org/127.crl
https://release-assets.githubusercontent.com/github-production-release-asset/165325376/3628bff7-ac5e-48e2-adb6-f753b93a65b5?sp=r&sv=2018-11-09&sr=b&spr=https&se=2026-09-17t07%3a36%3a12z&rscd=attachment%3b+filename%3dfido.ps1.lzma&rsct=application%2foctet-stream&skoid=96c2d410-5711-43a1-aedd-ab1947aa7ab0&sktid=398a6654-997b-47e9-b12b-9515b896b4de&skt=2026-09-17t06%3a36%3a05z&ske=2026-09-17t07%3a36%3a12z&sks=b&skv=2018-11-09&sig=5smlyay7djqwejsu2ipl4z2mjctanc0rfdzgpmi4zq8%3d&jwt=eyj0exaioijkv1qilcjhbgcioijiuzi1nij9.eyjpc3mioijnaxrodwiuy29tiiwiyxvkijoicmvszwfzzs1hc3nldhmuz2l0ahvidxnlcmnvbnrlbnquy29tiiwia2v5ijoia2v5msisimv4cci6mtc4otyynzkzoswibmjmijoxnzg5nji3njm5lcjwyxroijoicmvszwfzzwfzc2v0chjvzhvjdglvbi5ibg9ilmnvcmuud2luzg93cy5uzxqifq.ax0qf145dt0u4cs-lkepzwlckjuh64kfb6lmgs2qszc&response-content-disposition=attachment%3b%20filename%3dfido.ps1.lzma&response-content-type=application%2foctet-stream
https://login.live.com/ppsecure/deviceaddcredential.srf
https://settings-win.data.microsoft.com/settings/v3.0/wsd/waasassessment?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&ring=retail&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=bad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=10.0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=waasassessment&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&servicingbranch=cb&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&honorwufbdeferrals=0&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
https://settings-win.data.microsoft.com/settings/v3.0/wsd/muse?processorclockspeed=3094&flightids=&updateoffereddays=4294967295&branchreadinesslevel=cb&oemmanufacturername=dell&isclouddomainjoined=0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&sku=48&activationchannel=retail&attrdataver=186&ismdmenrolled=0&processorcores=6&processormodel=amd%20ryzen%205%203500%206-core%20processor&totalphysicalram=6144&primarydisktype=4294967295&flightingbranchname=&chassistypeid=1&oemmodelnumber=dell&systemvolumetotalcapacity=260281&sampleid=95271487&deviceclass=windows.desktop&app=muse&disabledualscan=0&appver=10.0&oemsubmodel=j5cr&locale=en-us&isalwaysonalwaysconnectedcapable=0&ms=0&defaultuserregion=244&updateserviceurl=http%3a%2f%2fneverupdatewindows10.com&osver=10.0.19045.4046.amd64fre.vb_release.191206-1406&os=windows&deviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&deferqualityupdateperiodindays=0&ring=retail&deferfeatureupdateperiodindays=30
http://ocsp.sectigo.com/mfewtzbnmeswstajbgurdgmcgguabbs3dhjwomgbojfu%2fpy58baob6amcwquf5mobmfv5c1wqaoqpqpt6rq4jmmcehj4ro8q5ndp2hoobwghs28%3d
Last Seen at

Recent blog posts

post image
How MSSPs Can Prove Their Value When “Nothing...
watchers 1738
comments 0
post image
Enterprise Threat Intelligence Buying Guide:...
watchers 2058
comments 0
post image
ANY.RUN & SentinelOne: One Workspace, Ins...
watchers 3705
comments 0

Key Takeaways

  • Credential and Data Theft: RatonRAT can steal credentials and collect system and hardware information from compromised Windows systems.
  • Persistence Mechanisms: The malware uses scheduled tasks and Active Setup to maintain execution after user logon.
  • Defense Evasion: RatonRAT can bypass PowerShell ExecutionPolicy and add its process to Microsoft Defender exclusions.
  • System and VM Discovery: It checks running processes, privileges, BIOS and disk information, as well as VirtualBox and VMware environments.
  • C2 Communication: After establishing itself, RatonRAT connects to a configured command-and-control server to receive further instructions.
  • Configurable .NET Malware: The family uses a configurable .NET architecture and Costura/Fody to bundle its components.
  • ANY.RUN’s Interactive Sandbox analysis reveals a sequence involving self-relocation, BAT-based execution, persistence, Defender exclusion, virtual environment checks, and subsequent C2 communication.

RatonRAT detonated inside ANY.RUN’s Interactive Sandbox

RatonRAT detonated inside ANY.RUN’s Interactive Sandbox

What is RatonRAT?

RatonRAT is a .NET-based Remote Access Trojan targeting Windows systems. The malware provides attackers with remote access to compromised hosts and supports capabilities including credential theft, system information collection, persistence, and security evasion.

The family is characterized by its configurable architecture and the use of Costura/Fody to package .NET components. This allows different samples to maintain a similar underlying structure while using customized configurations.

Observed samples also demonstrate a focus on maintaining access and reducing visibility after execution. The malware can relocate itself to an application-data directory, establish automatic startup mechanisms, modify Microsoft Defender exclusions, and communicate with a configured C2 server.

How RatonRAT Impacts Businesses and Organizations

A RatonRAT infection can create several risks for businesses and organizations:

  • Credential exposure: The malware can collect credentials from compromised systems, potentially exposing access to corporate services and applications.
  • Unauthorized remote access: As a RAT, RatonRAT provides attackers with a channel for remote control and further interaction with an infected endpoint.
  • Persistence: Scheduled tasks and Active Setup entries can allow the malware to restart automatically after user logon or environment initialization.
  • Security control bypass: Changes to Microsoft Defender exclusions can reduce endpoint protection visibility and allow the malware to continue operating.
  • Reconnaissance: System, hardware, process, disk, BIOS, and privilege information can help attackers understand the compromised environment.
  • Virtualization awareness: Checks for VirtualBox and VMware can allow the malware to identify analysis or virtualized environments.
  • Follow-on activity: Once a C2 connection is established, additional behavior depends on the commands received by the infected client.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

Victimology: Who Can Be Affected?

RatonRAT targets Windows systems, making organizations that rely on Windows workstations and endpoints potentially exposed to the malware.

Its capabilities are not limited to a particular industry. Credential collection, system reconnaissance, persistence, and remote access are broadly applicable to attacks against corporate endpoints.

Because RatonRAT can receive instructions from a configured C2 server, the activity performed after infection may vary between samples and campaigns.

How Does RatonRAT Function?

Observing a RatonRAT sample inside ANY.RUN’s Interactive Sandbox shows a sequence focused on establishing a stable execution location, creating persistence, weakening endpoint protections, collecting information about the environment, and contacting the C2 server.

The general execution flow begins with the initial executable relocating itself, followed by BAT-based execution, persistence, security evasion, system reconnaissance, and C2 communication.

RatonRAT analysis in ANY.RUN’s Interactive Sandbox

RatonRAT analysis in ANY.RUN’s Interactive Sandbox

Stage 1: Self-Relocation and BAT Creation

Immediately after execution, an observed RatonRAT sample copies itself into: %APPDATA%\Roaming\PlatformRuntime\

The malware also creates a BAT file inside: %APPDATA%\Roaming\Temp\

The BAT filename frequently follows a pattern similar to: cleanup_[a-z0-9]{30}.bat

The exact filename and script contents can vary between samples, but the overall structure remains similar.

The BAT script uses helper commands through cmd.exe and timeout.exe. It launches the relocated executable and attempts to remove the original executable from the desktop, helping the malware continue execution from its new location while cleaning up traces of the initial file.

RatonRAT creating a BAT launcher and relocating itself

RatonRAT creating a BAT launcher and relocating itself

Stage 2: BAT-Based Execution

The newly created BAT file is subsequently executed. Its primary purpose is to start the copied RatonRAT executable from the %APPDATA%\Roaming\PlatformRuntime\ directory.

The script also performs cleanup operations intended to remove traces of the original executable.

This creates an execution sequence in which the initial file is no longer the main execution location:

Original executable → BAT script → relocated RatonRAT copy

Stage 3: Establishing Persistence

After launching from its new location, RatonRAT proceeds to establish persistence.

One observed mechanism is a scheduled task configured to launch the malicious executable when the user logs in. The task can be created with elevated privileges, allowing the malware to regain execution automatically after login.

RatonRAT creating a scheduled task for persistence

RatonRAT creating a scheduled task for persistence

Some samples use a different persistence mechanism based on Active Setup rather than a scheduled task. Active Setup allows a component to execute automatically when the user's environment is initialized.

This variation demonstrates that persistence behavior can differ between RatonRAT samples while serving the same purpose: maintaining execution after the initial compromise.

RatonRAT using Active Setup to establish persistence

RatonRAT using Active Setup to establish persistence

Stage 4: PowerShell and Microsoft Defender Evasion

After persistence is established, RatonRAT launches PowerShell with an ExecutionPolicy bypass.

The malware also attempts to add its process to Microsoft Defender exclusions. This can reduce the ability of the endpoint security product to inspect or block the malicious process.

RatonRAT bypassing PowerShell ExecutionPolicy

RatonRAT bypassing PowerShell ExecutionPolicy

The combination of PowerShell execution and security-control modification represents an important behavioral signal for defenders investigating suspicious activity on Windows endpoints.

RatonRAT modifying Microsoft Defender exclusions

RatonRAT modifying Microsoft Defender exclusions

Stage 5: System and Virtual Environment Discovery

RatonRAT then collects information about the environment in which it is running.

Observed checks include:

  • VirtualBox indicators
  • VMware indicators
  • BIOS information
  • Disk information
  • Running processes
  • Available privileges
  • System and hardware characteristics

The virtualization checks can help the malware determine whether it is operating inside a virtualized or potentially analyzed environment.

RatonRAT checking for virtualization and system information

RatonRAT checking for virtualization and system information

Stage 6: Mutex Creation

Another characteristic observed during execution is the creation of randomly generated mutexes.

These mutex names vary between executions and samples, but their purpose is consistent with preventing multiple instances of the malware from running simultaneously or helping the malware coordinate its execution state.

RatonRAT creating a randomly generated mutex

RatonRAT creating a randomly generated mutex

Stage 7: C2 Communication

Once the malware is running from its intended directory, RatonRAT establishes network communication with its configured C2 server.

This connection provides the attacker with a channel for controlling the infected client and delivering further instructions.

RatonRAT communicating with its configured C2 server

RatonRAT communicating with its configured C2 server

The subsequent behavior depends on the commands received by the RatonRAT client. As a result, activity observed after the initial C2 connection can vary between infections.

RatonRAT Behavior at a Glance

The observed samples demonstrate several layers of activity designed to maintain execution and reduce the malware's visibility:

  • Relocation moves the executable from its original location into %APPDATA%\Roaming\PlatformRuntime.
  • BAT execution launches the relocated copy and attempts to remove the original file.
  • Persistence is established through scheduled tasks or Active Setup.
  • PowerShell is used with an ExecutionPolicy bypass.
  • Defender exclusions are modified to reduce security-tool interference.
  • Environment discovery collects system, hardware, process, privilege, and virtualization information.
  • Mutexes are created using randomized names.
  • C2 communication enables further remote instructions.

This combination gives RatonRAT multiple opportunities to survive execution, understand its environment, and maintain communication with its operator.

How Organizations Can Use ANY.RUN’s Threat Intelligence to Investigate RatonRAT

RatonRAT samples can vary in configuration, persistence mechanisms, filenames, and infrastructure. For this reason, relying exclusively on static indicators such as file hashes may provide limited visibility into related activity.

ANY.RUN’s Threat Intelligence can help analysts connect individual RatonRAT samples with related infrastructure, behavioral artifacts, and previous sandbox executions.

Threat Intelligence Lookup can be used to investigate known RatonRAT indicators and identify related artifacts.

threatName:"raton"

Searching for RatonRAT in ANY.RUN’s TI Lookup

Searching for RatonRAT in ANY.RUN’s TI Lookup

Identify Behavioral Indicators

Defenders investigating potential RatonRAT activity can monitor for combinations of behaviors such as:

  • Executables copying themselves into %APPDATA%\Roaming\PlatformRuntime\
  • BAT files created under %APPDATA%\Roaming\Temp\
  • BAT filenames matching cleanup_[a-z0-9]{30}.bat
  • cmd.exe and timeout.exe launched by suspicious scripts
  • Newly created scheduled tasks launching executables from user-writable directories
  • Active Setup entries associated with unexpected executables
  • PowerShell launched with an ExecutionPolicy bypass
  • Unexpected modifications to Microsoft Defender exclusions
  • VirtualBox or VMware environment checks by suspicious processes
  • Unusual BIOS, disk, process, or privilege discovery
  • Randomly generated mutex creation
  • Unexpected outbound connections to configured C2 infrastructure

Behavioral detection can be particularly useful because individual RatonRAT samples may use different filenames, configurations, or persistence mechanisms.

Powered by data contributed by 16,000 organizations and 700,000 security professionals, fresh ANY.RUN’s Threat Intelligence Feeds provide SOC teams with current indicators linked to RatonRAT activity. Feeds can be integrated with SIEM, SOAR, and EDR platforms, and other security solutions to help analysts detect suspicious infrastructure, investigate related activity, and track changes in the threat landscape.

Threat intelligence from 16K SOCs and 700K analysts

Threat intelligence from 16K SOCs and 700K analysts

Analysts can use ANY RUN’s Threat Intelligence Lookup to pivot from a suspicious sample or indicator toward related activity.

For example, an investigation can begin with a suspicious executable and expand to:

  • Related RatonRAT samples
  • Shared hashes and artifacts
  • C2 infrastructure
  • Similar BAT launchers
  • Persistence mechanisms
  • PowerShell activity
  • Common configuration characteristics
  • Previous sandbox executions

This approach can help analysts determine whether an isolated endpoint event is connected to broader RatonRAT activity.

Respond to a RatonRAT Infection

If RatonRAT is identified on a corporate endpoint, incident response should address both the compromised host and any credentials or sessions that may have been exposed.

Recommended actions include:

  • Isolate the affected endpoint.
  • Preserve relevant forensic evidence.
  • Remove unauthorized persistence mechanisms.
  • Reset credentials that may have been exposed.
  • Revoke active sessions where appropriate.
  • Review authentication logs for suspicious activity.
  • Investigate Microsoft Defender exclusion changes.
  • Search for related BAT files, scheduled tasks, Active Setup entries, and suspicious PowerShell activity.
  • Identify and block associated C2 infrastructure where appropriate.
  • Search other endpoints for matching behavioral indicators.

As RatonRAT can maintain persistence and communicate with a C2 server, removing the initial executable alone may not be sufficient to determine whether the system remains compromised.

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

RatonRAT demonstrates how a relatively compact Windows RAT can combine persistence, system reconnaissance, credential theft, defense evasion, and C2 communication into a single infection chain.

Observed samples relocate themselves, use BAT scripts for execution and cleanup, establish persistence through scheduled tasks or Active Setup, modify Microsoft Defender exclusions, inspect the host environment, and communicate with a configured C2 server.

For defenders, these behaviors provide multiple opportunities for detection. Monitoring persistence creation, suspicious PowerShell activity, Defender exclusion changes, user-writable execution paths, virtualization checks, and unexpected C2 communication can help identify RatonRAT activity beyond simple hash-based detection.

Frequently Asked Questions: RatonRAT

1. What is RatonRAT?

RatonRAT is a .NET-based Remote Access Trojan targeting Windows systems. It supports capabilities including credential theft, system information collection, persistence, security evasion, and remote communication with a C2 server.

2. What can RatonRAT do?

RatonRAT can collect credentials and system information, establish persistence, inspect the host environment, evade certain security controls, and communicate with an attacker-controlled C2 server for further instructions.

3. How does RatonRAT establish persistence?

Observed samples can create a scheduled task that launches the malware at user logon. Some variants instead use an Active Setup entry to automatically execute a component during user-environment initialization.

4. How can RatonRAT evade detection?

RatonRAT can launch PowerShell with an ExecutionPolicy bypass and add its process to Microsoft Defender exclusions. It also checks for virtualized environments and uses self-relocation and cleanup scripts to reduce traces of its initial execution.

5. What does RatonRAT check on an infected system?

Observed samples inspect BIOS and disk information, running processes, system and hardware characteristics, available privileges, and virtualization indicators associated with VirtualBox and VMware.

6. How can interactive sandboxing and threat intelligence help investigate RatonRAT?

Interactive sandboxing allows analysts to observe the malware's behavior in a controlled environment, including self-relocation, BAT execution, persistence creation, PowerShell activity, Defender exclusion changes, environment discovery, mutex creation, and C2 communication.

Threat intelligence can then be used to pivot from observed indicators to related samples and infrastructure.

HAVE A LOOK AT

Zloader screenshot
Zloader
zloader trojan loader
Zloader is a banking trojan that uses webinjects and VNC clients to still banking credentials. This Trojan is based on leaked code from 2011, but despite its age, Zloader’s popularity has been only increasing through early 2020, when it relied on COVID-19 themed attacks.
Read More
DarkTortilla screenshot
DarkTortilla
darktortilla
DarkTortilla is a crypter used by attackers to spread harmful software. It can modify system files to stay hidden and active. DarkTortilla is a multi-stage crypter that relies on several components to operate. It is often distributed through phishing sites that look like real services.
Read More
Bert Ransomware screenshot
Bert Ransomware is a newly emerged ransomware group that has been active since April 2025. It deploys variants targeting both Windows and Linux systems, focusing on critical sectors like healthcare, technology, and event services across the US, Asia, and Europe.
Read More
GravityRAT screenshot
GravityRAT
gravity
GravityRAT is a sophisticated spyware and remote access trojan that has been actively targeting organizations and government entities since 2016. It uses innovative anti-analysis techniques and made an evolution from a Windows-only threat to a cross-platform espionage tool capable of compromising Windows, Android, and macOS systems.
Read More
DarkVision screenshot
DarkVision
darkvision
DarkVision RAT is a low-cost, modular Remote Access Trojan that gives attackers remote control of infected Windows hosts. Initially observed around 2020 and sold in underground marketplaces, DarkVision has become notable for its full feature set (keylogging, screen capture, file theft, remote command execution and plugin support) and for being distributed via multi-stage loaders in recent campaigns.
Read More
SSLoad screenshot
SSLoad
ssload
SSLoad is a malicious loader or downloader that is used to infiltrate target systems through phishing emails, perform reconnaissance and transmit it back to its operators delivering malicious payloads. To avoid detection, SSLoad employs various encryption methods and delivery techniques highlighting its versatile nature and complexity. It is believed to be a part of Malware-as-a-Service (MaaS) operation given its diverse delivery methods and implemented techniques.
Read More