Skip to content
Malware family

BitRAT

BitRAT is a Windows remote access trojan (RAT) and a descendant of the AsyncRAT malware family.

Profile source: Mallory opens in a new tab

BitRAT

Family profile

BitRAT is a Windows remote access trojan (RAT) and a descendant of the AsyncRAT malware family. Censys mapped its lineage as AsyncRAT β†’ DCRAT (DarkCrystal RAT) β†’ BitRAT, alongside related forks such as VenomRAT, EchoRAT, Gh0stRAT, CyberSpike, Dumpling RAT, and DarkRAT. The malware appears in reporting as a commodity/open-source or cracked RAT used in multi-stage intrusion chains and malware delivery ecosystems.

BitRAT has been observed or referenced in campaigns involving multiple threat actors and delivery chains. Reporting cited it among the RATs used by TAG-144 / Blind Eagle, which has targeted Colombian government entities and other organizations in South America via spearphishing and staged payload delivery. Kaspersky also reported BlindEagle rotating among open-source RATs including BitRAT. BitRAT was additionally reported as a companion payload in campaigns delivering Rhadamanthys, and historical reporting on the Blister loader noted a campaign that reportedly dropped Cobalt Strike and BitRAT. Check Point also listed BitRAT among malware families delivered by the dotRunpeX injector.

Infrastructure and detection reporting directly tie BitRAT to command-and-control activity. As of 16 June 2026, Censys had confirmed one BitRAT command-and-control host, tracked as THREAT-0162. Censys assessed inherited DCRAT TLS certificate metadata as the most reliable detection signal across the broader AsyncRAT family, including BitRAT. The reported family-wide indicator is self-signed TLS certificates on non-standard ports with subject/issuer patterns such as "O=<Name> By <author>, L=SH, C=CN," with variant names and builder handles appearing in certificate fields. A Nuclei template exists for BitRAT C2 detection at ssl/c2/bitrat-c2.yaml, and public references also point to Censys hunting queries for BitRAT infrastructure.

BitRAT is also referenced in underground-market advertising as an "advanced Windows RAT," further supporting its role as a commodity Windows remote administration malware family. High-confidence content does not provide additional verified technical details here on its internal modules, persistence, or specific data-theft functions beyond its classification and observed use as a RAT.

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Jul 18, 2026
Last activity
Jul 20, 2026
Feed role
C2
Host form
0 IP / 3 hostnames

Leading locations

  • US1

Leading providers

  • Wowrack.com1

Infrastructure traits

  • Hosting 1

Samples

Recent associated samples

Reported operators

Threat actors

1 named in public reporting
APT-C-36

TAG-144 leverages a range of commodity remote access trojans (RATs), including AsyncRAT, REMCOS RAT, DcRAT, njRAT, LimeRAT, QuasarRAT, BitRAT, and a Quasar variant known as BlotchyQuasar.

MITRE ATT&CK

BitRAT in ATT&CK

6 distinct techniques

Reporting

Research mentioning BitRAT

Jun 30
Cyberveille

AsyncRAT Family : cartographie de 40 variants RAT et leur infrastructure C2 active | CyberVeille

DCRAT β†’ VenomRAT, EchoRAT, Gh0stRAT, BitRAT, CyberSpike, Dumpling RAT, DarkRAT (via ShaShenRAT)

Apr 15
Stealthmole Intelligence Hub

StealthMole Intelligence Hub: From XpertTechy to BlackHat Tools: Uncovering a Multi-Layered Malware Distribution Network

https://darkne*****y.com/threads/bitrat-advanced-windows-rat-fully-activated.37563/

Jan 9
Nuclei Templates Pull Requests

Use boolean for verified metadata in BitRAT C2 template

Updated template: ssl/c2/bitrat-c2.yaml Fix: metadata.verified was set as a quoted string ("true"). Changed it to a boolean (true) for schema consistency and to avoid tooling/parsing inconsistencies. References: https://github.com/thehappydinoa/awesome-censys-queries#bitrat--

Nov 12
Proofpoint Threat Insight

Operation Endgame Quakes Rhadamanthys | Proofpoint US

Proofpoint researchers have also observed Rhadamanthys delivered in campaigns as a companion to other malware, including: Remcos zgRAT Screenshotter / AHK Bot BitRAT XWorm Lumma XLoader

Aug 26
Recorded Future

TAG-144’s Persistent Grip on South American Organizations

TAG-144 leverages a range of commodity remote access trojans (RATs), including AsyncRAT, REMCOS RAT, DcRAT, njRAT, LimeRAT, QuasarRAT, BitRAT, and a Quasar variant known as BlotchyQuasar.

Nov 1
Ncc Group Research

Popping Blisters for research: An overview of past payloads and exploring recent developments

That campaign reportedly dropped Cobalt Strike and BitRat.

Oct 17
Securelist

APT trends report Q3 2023 | Securelist

BlindEagle ... cycle through various open-source remote access Trojans (RATs) such as AsyncRAT, Lime-RAT and BitRAT...

Mar 15
Checkpoint Research

DotRunpeX - demystifying new virtualized .NET injector used in the wild - Check Point Research

Among the variety of downloaders and cryptocurrency stealers, we spotted these known malware families delivered by dotRunpeX: ... BitRAT ...

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.