Skip to content

BitRAT

BitRAT is a commercial, low-cost Windows remote-access trojan marketed on underground cybercrime forums since 2020.

Profile source: Mallory opens in a new tab

BitRAT

Family profile

BitRAT is a commercial, low-cost Windows remote-access trojan marketed on underground cybercrime forums since 2020. It provides operators with remote control of compromised systems, including file, process, service, application, and Windows-management functions. Documented capabilities include command and payload execution, data exfiltration, browser and application credential theft, keylogging, clipboard monitoring, webcam and microphone capture, hidden-VNC and remote-desktop access, SOCKS proxying, cryptocurrency mining, and denial-of-service attacks. BitRAT variants have also implemented UAC bypass and Windows Defender evasion or deactivation.

BitRAT has been delivered through phishing and malspam campaigns, malicious Office documents and macros, password-protected archives, trojanized software, fake browser updates, unofficial Windows activation tools, watering-hole activity, and NFT-themed lures. Loaders and crypters have deployed it through reflective loading and process injection, including process hollowing. Persistence mechanisms observed in BitRAT delivery chains include Startup-folder execution, scheduled tasks, and Run-key persistence.

The malware has been used by multiple cybercrime operations and alongside other commodity malware. APT-C-36, also known as Blind Eagle, deployed BitRAT in spear-phishing campaigns targeting organizations primarily in Colombia and elsewhere in South America, including government, financial, healthcare, telecommunications, energy, and oil and gas entities. Other observed campaigns have targeted Windows users seeking pirated software, German automotive organizations, and NFT-focused users.

Capabilities

  • Credential Theft
  • Crypto Theft
  • Ddos
  • Defense Evasion
  • Exfiltration
  • Keylogging
  • Persistence
  • Privilege Escalation
  • Process Injection

Reported operators

Threat actors

3 named in public reporting
APT-C-36

“After deobfuscating the executable file within the password-protected archive, we are presented with a RAT called BitRAT.”

Water Basilisk

In some cases, the final stage PowerShell script contained up to seven various RATs. These are typically NjRat, BitRat, Nanocore RAT, QuasarRat, LimeRat, and Warzone.

DDGroup

all of them have been associated with off-the-shelf malware like QuasarRAT, BitRat, and similar.

MITRE ATT&CK

BitRAT in ATT&CK

63 distinct techniques

Techniques

63 techniques
T1140 Deobfuscate/Decode Files or Information T1055 Process Injection T1204.002 Malicious File T1027.013 Encrypted/Encoded File T1071.001 Web Protocols T1566.002 Spearphishing Link T1071 Application Layer Protocol T1105 Ingress Tool Transfer T1555 Credentials from Password Stores T1218.005 Mshta T1059.001 PowerShell T1125 Video Capture T1189 Drive-by Compromise T1059 Command and Scripting Interpreter T1115 Clipboard Data T1548.002 Bypass User Account Control T1566 Phishing T1486 Data Encrypted for Impact T1056.001 Keylogging T1496 Resource Hijacking T1123 Audio Capture T1057 Process Discovery T1059.005 Visual Basic T1562 Impair Defenses T1053.005 Scheduled Task T1070.004 File Deletion T1497 Virtualization/Sandbox Evasion T1036 Masquerading T1204 User Execution T1047 Windows Management Instrumentation T1059.007 JavaScript T1055.012 Process Hollowing T1218 System Binary Proxy Execution T1547.001 Registry Run Keys / Startup Folder T1059.003 Windows Command Shell T1573 Encrypted Channel T1566.001 Spearphishing Attachment T1027 Obfuscated Files or Information T1620 Reflective Code Loading T1219 Remote Access Tools T1568 Dynamic Resolution T1090 Proxy T1218.011 Rundll32 T1027.002 Software Packing T1041 Exfiltration Over C2 Channel T1497.001 System Checks T1106 Native API T1102 Web Service T1027.007 Dynamic API Resolution T1584 Compromise Infrastructure T1498 Network Denial of Service T1560 Archive Collected Data T1548 Abuse Elevation Control Mechanism T1547 Boot or Logon Autostart Execution T1132 Data Encoding T1113 Screen Capture T1499 Endpoint Denial of Service T1564.004 NTFS File Attributes T1564.003 Hidden Window T1583.003 Virtual Private Server T1587.001 Malware T1588.001 Malware T1021.005 VNC

Reporting

Research mentioning BitRAT

Aug 12
Cylance Threatvector

Blog | Arctic Wolf

AZORult, a long-running credential-stealing malware family tied to the Genesis Store cybercrime marketplace, has continued to appear in new delivery campaigns despite earlier reports that browser security changes had crippled its core theft capabilities. Earlier research linked more than 300,000 infections sold through Genesis to AZORult or its suppliers, showing how the malware fit into a broader malware-as-a-service and stolen-access supply chain. Although a Google Chrome update was reported to have disrupted older AZORult builds and pushed some criminal operators toward other stealers, subsequent activity indicates the malware remained in circulation through updated or repackaged campaigns. Recent and historical reporting shows AZORult being distributed through spam emails, ZIP or ISO archives, malicious LNK and HTA files, and heavily obfuscated script chains using PowerShell, batch files, JavaScript, and scheduled tasks. The malware has been used against targets including Korean users and German automotive businesses, where it stole browser credentials, cookies, autofill data, email and messaging app data, cryptocurrency wallet files, screenshots, and system information, while also supporting follow-on payload delivery. Newer campaigns emphasized in-memory execution, anti-analysis checks, and minimal disk artifacts to evade detection, underscoring AZORult's persistence as a commodity infostealer within a more outsourced and opportunistic cybercrime ecosystem.

Jul 17
Levelblue Spiderlabs

Still Circling: Blind Eagle's Toolkit Keeps Evolving

Blind Eagle, also tracked as TAG-144, APT-C-36, and linked by some researchers to Red Akodon, continued targeting organizations across South America with a sustained emphasis on Colombian government entities at the local, municipal, and federal levels. Researchers described multi-stage intrusion chains using spearphishing, including compromised Colombian government email accounts, to deliver commodity and cracked remote access trojans through exposed Apache staging servers, dynamic DNS infrastructure, and legitimate internet services used for payload staging. The group has remained active since at least 2018, blending credential theft, financial crime, and surveillance-oriented collection against public-sector targets. Recent activity shows the actor refining rather than replacing its established toolkit. Investigators observed VBScript-to-PowerShell delivery chains, steganography to conceal payloads in image files, a new JavaScript stage with custom AES-based string obfuscation, an AutoIt3 RunPE loader fetched from raw.githubusercontent.com, and repeated use of the "Photo Studio" persistence disguise. The most significant upgrade was a new AsyncRAT variant, JC-46, which adds WNF-based process injection, custom Base28 encoding, HVNC support for banking fraud, browser profile cloning, and a bypass for Chrome App-Bound Encryption v20, while the group continued reusing VPN-linked command-and-control infrastructure and familiar dynamic DNS patterns.

Aug 26
Recorded Future

TAG-144’s Persistent Grip on South American Organizations

Apr 18
Morphisec

NFT Malware Gets New Evasion Abilities

Threat actors targeted cryptocurrency and NFT communities with phishing messages and spoofed NFT project websites that impersonated legitimate services to trick users into downloading malware. One campaign used a fake Pixelmon site, pixelmon[.]pw, to mimic the real project and deliver ZIP archives containing Windows shortcut and script payloads that installed Vidar infostealer, which steals passwords, cryptocurrency wallet data, and sensitive files. Researchers found Vidar obtained command-and-control details through a Telegram channel and could fetch additional modules from its C2 infrastructure. A separate but related campaign tracked as NFT-001 used Discord and similar forums to lure victims to decoy crypto sites, where a malicious installer deployed Remcos RAT and, in newer variants, Eternity Stealer. Morphisec reported the operators changed tooling from the Babadeda crypter to a staged downloader while keeping similar delivery infrastructure and some overlapping C2 elements. The newer downloader performed a UAC bypass, added C:\ to Microsoft Defender exclusions, and retrieved follow-on payloads to improve evasion and credential theft, showing continued refinement of malware delivery against NFT and crypto users.

Jan 12
Cyble

Sneaky Azorult Back In Action And Goes Undetected - Cyble

Jan 3
Ahnlab Asec

Orcus RAT Being Distributed Disguised as a Hangul Word Processor Crack - ASEC

A malware campaign targeting Korean users distributed Orcus RAT and XMRig by disguising the payload as a cracked installer for Hangul Word Processor 2022 on file-sharing sites. AhnLab said the installer used 7z SFX archives, obfuscated PowerShell, Windows Defender exclusion changes, Google Docs-hosted payload retrieval, NirCmd, and scheduled tasks to evade detection and maintain persistence. The downloader checked for analysis environments and installed security tools, exfiltrated host details through the Telegram API, and then selectively deployed a coin miner or additional malware components. On some systems, particularly those with Telegram or Visual Studio installed, the actor installed Orcus RAT and enabled broad remote access, including keylogging, webcam access, remote desktop control, and RDP activation through an OrcusRDP account. The activity reflects the continued criminal use of Orcus, a commercially sold modular RAT previously documented by Palo Alto Networks Unit 42 as a low-cost malware platform with plugin support and live scripting capabilities. Unit 42 reported that Orcus was built around separate controller, server, and victim components and supported functions such as password theft, remote code execution, webcam and microphone monitoring, reverse proxying, and hidden virtual network computing. The Korean campaign also showed anti-analysis behavior consistent with Orcus tradecraft, including checks for virtualized environments and monitoring tools, while the bundled XMRig miner was injected into explorer.exe, paused during games or monitoring activity, and attempted to kill security-related processes to hinder remediation.

May 15
Bleeping Computer

Fake Pixelmon NFT site infects you with password-stealing malware

May 10
Checkpoint

Info-stealer Campaign targets German Car Dealerships and Manufacturers - Check Point Blog

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.