“After deobfuscating the executable file within the password-protected archive, we are presented with a RAT called BitRAT.”
BitRAT
BitRAT is a commercial, low-cost Windows remote-access trojan marketed on underground cybercrime forums since 2020.
Profile source: Mallory opens in a new tabBitRAT
Family profile
BitRAT is a commercial, low-cost Windows remote-access trojan marketed on underground cybercrime forums since 2020. It provides operators with remote control of compromised systems, including file, process, service, application, and Windows-management functions. Documented capabilities include command and payload execution, data exfiltration, browser and application credential theft, keylogging, clipboard monitoring, webcam and microphone capture, hidden-VNC and remote-desktop access, SOCKS proxying, cryptocurrency mining, and denial-of-service attacks. BitRAT variants have also implemented UAC bypass and Windows Defender evasion or deactivation.
BitRAT has been delivered through phishing and malspam campaigns, malicious Office documents and macros, password-protected archives, trojanized software, fake browser updates, unofficial Windows activation tools, watering-hole activity, and NFT-themed lures. Loaders and crypters have deployed it through reflective loading and process injection, including process hollowing. Persistence mechanisms observed in BitRAT delivery chains include Startup-folder execution, scheduled tasks, and Run-key persistence.
The malware has been used by multiple cybercrime operations and alongside other commodity malware. APT-C-36, also known as Blind Eagle, deployed BitRAT in spear-phishing campaigns targeting organizations primarily in Colombia and elsewhere in South America, including government, financial, healthcare, telecommunications, energy, and oil and gas entities. Other observed campaigns have targeted Windows users seeking pirated software, German automotive organizations, and NFT-focused users.
Capabilities
- Credential Theft
- Crypto Theft
- Ddos
- Defense Evasion
- Exfiltration
- Keylogging
- Persistence
- Privilege Escalation
- Process Injection
Reported operators
Threat actors
3 named in public reportingIn some cases, the final stage PowerShell script contained up to seven various RATs. These are typically NjRat, BitRat, Nanocore RAT, QuasarRat, LimeRat, and Warzone.
all of them have been associated with off-the-shelf malware like QuasarRAT, BitRat, and similar.
MITRE ATT&CK
BitRAT in ATT&CK
63 distinct techniquesTechniques
63 techniquesReporting
Research mentioning BitRAT
Blog | Arctic Wolf
AZORult, a long-running credential-stealing malware family tied to the Genesis Store cybercrime marketplace, has continued to appear in new delivery campaigns despite earlier reports that browser security changes had crippled its core theft capabilities. Earlier research linked more than 300,000 infections sold through Genesis to AZORult or its suppliers, showing how the malware fit into a broader malware-as-a-service and stolen-access supply chain. Although a Google Chrome update was reported to have disrupted older AZORult builds and pushed some criminal operators toward other stealers, subsequent activity indicates the malware remained in circulation through updated or repackaged campaigns. Recent and historical reporting shows AZORult being distributed through spam emails, ZIP or ISO archives, malicious LNK and HTA files, and heavily obfuscated script chains using PowerShell, batch files, JavaScript, and scheduled tasks. The malware has been used against targets including Korean users and German automotive businesses, where it stole browser credentials, cookies, autofill data, email and messaging app data, cryptocurrency wallet files, screenshots, and system information, while also supporting follow-on payload delivery. Newer campaigns emphasized in-memory execution, anti-analysis checks, and minimal disk artifacts to evade detection, underscoring AZORult's persistence as a commodity infostealer within a more outsourced and opportunistic cybercrime ecosystem.
Still Circling: Blind Eagle's Toolkit Keeps Evolving
Blind Eagle, also tracked as TAG-144, APT-C-36, and linked by some researchers to Red Akodon, continued targeting organizations across South America with a sustained emphasis on Colombian government entities at the local, municipal, and federal levels. Researchers described multi-stage intrusion chains using spearphishing, including compromised Colombian government email accounts, to deliver commodity and cracked remote access trojans through exposed Apache staging servers, dynamic DNS infrastructure, and legitimate internet services used for payload staging. The group has remained active since at least 2018, blending credential theft, financial crime, and surveillance-oriented collection against public-sector targets. Recent activity shows the actor refining rather than replacing its established toolkit. Investigators observed VBScript-to-PowerShell delivery chains, steganography to conceal payloads in image files, a new JavaScript stage with custom AES-based string obfuscation, an AutoIt3 RunPE loader fetched from raw.githubusercontent.com, and repeated use of the "Photo Studio" persistence disguise. The most significant upgrade was a new AsyncRAT variant, JC-46, which adds WNF-based process injection, custom Base28 encoding, HVNC support for banking fraud, browser profile cloning, and a bypass for Chrome App-Bound Encryption v20, while the group continued reusing VPN-linked command-and-control infrastructure and familiar dynamic DNS patterns.
TAG-144’s Persistent Grip on South American Organizations
NFT Malware Gets New Evasion Abilities
Threat actors targeted cryptocurrency and NFT communities with phishing messages and spoofed NFT project websites that impersonated legitimate services to trick users into downloading malware. One campaign used a fake Pixelmon site, pixelmon[.]pw, to mimic the real project and deliver ZIP archives containing Windows shortcut and script payloads that installed Vidar infostealer, which steals passwords, cryptocurrency wallet data, and sensitive files. Researchers found Vidar obtained command-and-control details through a Telegram channel and could fetch additional modules from its C2 infrastructure. A separate but related campaign tracked as NFT-001 used Discord and similar forums to lure victims to decoy crypto sites, where a malicious installer deployed Remcos RAT and, in newer variants, Eternity Stealer. Morphisec reported the operators changed tooling from the Babadeda crypter to a staged downloader while keeping similar delivery infrastructure and some overlapping C2 elements. The newer downloader performed a UAC bypass, added C:\ to Microsoft Defender exclusions, and retrieved follow-on payloads to improve evasion and credential theft, showing continued refinement of malware delivery against NFT and crypto users.
Sneaky Azorult Back In Action And Goes Undetected - Cyble
Orcus RAT Being Distributed Disguised as a Hangul Word Processor Crack - ASEC
A malware campaign targeting Korean users distributed Orcus RAT and XMRig by disguising the payload as a cracked installer for Hangul Word Processor 2022 on file-sharing sites. AhnLab said the installer used 7z SFX archives, obfuscated PowerShell, Windows Defender exclusion changes, Google Docs-hosted payload retrieval, NirCmd, and scheduled tasks to evade detection and maintain persistence. The downloader checked for analysis environments and installed security tools, exfiltrated host details through the Telegram API, and then selectively deployed a coin miner or additional malware components. On some systems, particularly those with Telegram or Visual Studio installed, the actor installed Orcus RAT and enabled broad remote access, including keylogging, webcam access, remote desktop control, and RDP activation through an OrcusRDP account. The activity reflects the continued criminal use of Orcus, a commercially sold modular RAT previously documented by Palo Alto Networks Unit 42 as a low-cost malware platform with plugin support and live scripting capabilities. Unit 42 reported that Orcus was built around separate controller, server, and victim components and supported functions such as password theft, remote code execution, webcam and microphone monitoring, reverse proxying, and hidden virtual network computing. The Korean campaign also showed anti-analysis behavior consistent with Orcus tradecraft, including checks for virtualized environments and monitoring tools, while the bundled XMRig miner was injected into explorer.exe, paused during games or monitoring activity, and attempted to kill security-related processes to hinder remediation.