TAG-144 leverages a range of commodity remote access trojans (RATs), including AsyncRAT, REMCOS RAT, DcRAT, njRAT, LimeRAT, QuasarRAT, BitRAT, and a Quasar variant known as BlotchyQuasar.
BitRAT
BitRAT is a Windows remote access trojan (RAT) and a descendant of the AsyncRAT malware family.
Profile source: Mallory opens in a new tabBitRAT
Family profile
BitRAT is a Windows remote access trojan (RAT) and a descendant of the AsyncRAT malware family. Censys mapped its lineage as AsyncRAT → DCRAT (DarkCrystal RAT) → BitRAT, alongside related forks such as VenomRAT, EchoRAT, Gh0stRAT, CyberSpike, Dumpling RAT, and DarkRAT. The malware appears in reporting as a commodity/open-source or cracked RAT used in multi-stage intrusion chains and malware delivery ecosystems.
BitRAT has been observed or referenced in campaigns involving multiple threat actors and delivery chains. Reporting cited it among the RATs used by TAG-144 / Blind Eagle, which has targeted Colombian government entities and other organizations in South America via spearphishing and staged payload delivery. Kaspersky also reported BlindEagle rotating among open-source RATs including BitRAT. BitRAT was additionally reported as a companion payload in campaigns delivering Rhadamanthys, and historical reporting on the Blister loader noted a campaign that reportedly dropped Cobalt Strike and BitRAT. Check Point also listed BitRAT among malware families delivered by the dotRunpeX injector.
Infrastructure and detection reporting directly tie BitRAT to command-and-control activity. As of 16 June 2026, Censys had confirmed one BitRAT command-and-control host, tracked as THREAT-0162. Censys assessed inherited DCRAT TLS certificate metadata as the most reliable detection signal across the broader AsyncRAT family, including BitRAT. The reported family-wide indicator is self-signed TLS certificates on non-standard ports with subject/issuer patterns such as "O=<Name> By <author>, L=SH, C=CN," with variant names and builder handles appearing in certificate fields. A Nuclei template exists for BitRAT C2 detection at ssl/c2/bitrat-c2.yaml, and public references also point to Censys hunting queries for BitRAT infrastructure.
BitRAT is also referenced in underground-market advertising as an "advanced Windows RAT," further supporting its role as a commodity Windows remote administration malware family. High-confidence content does not provide additional verified technical details here on its internal modules, persistence, or specific data-theft functions beyond its classification and observed use as a RAT.
Reported operators
Threat actors
1 named in public reportingMITRE ATT&CK
BitRAT in ATT&CK
6 distinct techniquesReporting
Research mentioning BitRAT
Still Circling: Blind Eagle's Toolkit Keeps Evolving
Blind Eagle, also tracked as TAG-144, APT-C-36, and linked by some researchers to Red Akodon, continued targeting organizations across South America with a sustained emphasis on Colombian government entities at the local, municipal, and federal levels. Researchers described multi-stage intrusion chains using spearphishing, including compromised Colombian government email accounts, to deliver commodity and cracked remote access trojans through exposed Apache staging servers, dynamic DNS infrastructure, and legitimate internet services used for payload staging. The group has remained active since at least 2018, blending credential theft, financial crime, and surveillance-oriented collection against public-sector targets. Recent activity shows the actor refining rather than replacing its established toolkit. Investigators observed VBScript-to-PowerShell delivery chains, steganography to conceal payloads in image files, a new JavaScript stage with custom AES-based string obfuscation, an AutoIt3 RunPE loader fetched from raw.githubusercontent.com, and repeated use of the "Photo Studio" persistence disguise. The most significant upgrade was a new AsyncRAT variant, JC-46, which adds WNF-based process injection, custom Base28 encoding, HVNC support for banking fraud, browser profile cloning, and a bypass for Chrome App-Bound Encryption v20, while the group continued reusing VPN-linked command-and-control infrastructure and familiar dynamic DNS patterns.