Last seven days
- First activity
- Jul 18, 2026
- Last activity
- Jul 20, 2026
- Feed role
- C2
- Host form
- 0 IP / 3 hostnames
BitRAT is a Windows remote access trojan (RAT) and a descendant of the AsyncRAT malware family.
Profile source: Mallory opens in a new tabBitRAT
BitRAT is a Windows remote access trojan (RAT) and a descendant of the AsyncRAT malware family. Censys mapped its lineage as AsyncRAT β DCRAT (DarkCrystal RAT) β BitRAT, alongside related forks such as VenomRAT, EchoRAT, Gh0stRAT, CyberSpike, Dumpling RAT, and DarkRAT. The malware appears in reporting as a commodity/open-source or cracked RAT used in multi-stage intrusion chains and malware delivery ecosystems.
BitRAT has been observed or referenced in campaigns involving multiple threat actors and delivery chains. Reporting cited it among the RATs used by TAG-144 / Blind Eagle, which has targeted Colombian government entities and other organizations in South America via spearphishing and staged payload delivery. Kaspersky also reported BlindEagle rotating among open-source RATs including BitRAT. BitRAT was additionally reported as a companion payload in campaigns delivering Rhadamanthys, and historical reporting on the Blister loader noted a campaign that reportedly dropped Cobalt Strike and BitRAT. Check Point also listed BitRAT among malware families delivered by the dotRunpeX injector.
Infrastructure and detection reporting directly tie BitRAT to command-and-control activity. As of 16 June 2026, Censys had confirmed one BitRAT command-and-control host, tracked as THREAT-0162. Censys assessed inherited DCRAT TLS certificate metadata as the most reliable detection signal across the broader AsyncRAT family, including BitRAT. The reported family-wide indicator is self-signed TLS certificates on non-standard ports with subject/issuer patterns such as "O=<Name> By <author>, L=SH, C=CN," with variant names and builder handles appearing in certificate fields. A Nuclei template exists for BitRAT C2 detection at ssl/c2/bitrat-c2.yaml, and public references also point to Censys hunting queries for BitRAT infrastructure.
BitRAT is also referenced in underground-market advertising as an "advanced Windows RAT," further supporting its role as a commodity Windows remote administration malware family. High-confidence content does not provide additional verified technical details here on its internal modules, persistence, or specific data-theft functions beyond its classification and observed use as a RAT.
C2 tracking
Derp observations, rolling seven-day window
Samples
Reported operators
TAG-144 leverages a range of commodity remote access trojans (RATs), including AsyncRAT, REMCOS RAT, DcRAT, njRAT, LimeRAT, QuasarRAT, BitRAT, and a Quasar variant known as BlotchyQuasar.
MITRE ATT&CK
Reporting
DCRAT β VenomRAT, EchoRAT, Gh0stRAT, BitRAT, CyberSpike, Dumpling RAT, DarkRAT (via ShaShenRAT)
https://darkne*****y.com/threads/bitrat-advanced-windows-rat-fully-activated.37563/
Updated template: ssl/c2/bitrat-c2.yaml Fix: metadata.verified was set as a quoted string ("true"). Changed it to a boolean (true) for schema consistency and to avoid tooling/parsing inconsistencies. References: https://github.com/thehappydinoa/awesome-censys-queries#bitrat--
Proofpoint researchers have also observed Rhadamanthys delivered in campaigns as a companion to other malware, including: Remcos zgRAT Screenshotter / AHK Bot BitRAT XWorm Lumma XLoader
TAG-144 leverages a range of commodity remote access trojans (RATs), including AsyncRAT, REMCOS RAT, DcRAT, njRAT, LimeRAT, QuasarRAT, BitRAT, and a Quasar variant known as BlotchyQuasar.
That campaign reportedly dropped Cobalt Strike and BitRat.
BlindEagle ... cycle through various open-source remote access Trojans (RATs) such as AsyncRAT, Lime-RAT and BitRAT...
Among the variety of downloaders and cryptocurrency stealers, we spotted these known malware families delivered by dotRunpeX: ... BitRAT ...
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.