Skip to content

BitRAT

BitRAT is a Windows remote access trojan (RAT) and a descendant of the AsyncRAT malware family.

Profile source: Mallory opens in a new tab

BitRAT

Family profile

BitRAT is a Windows remote access trojan (RAT) and a descendant of the AsyncRAT malware family. Censys mapped its lineage as AsyncRAT → DCRAT (DarkCrystal RAT) → BitRAT, alongside related forks such as VenomRAT, EchoRAT, Gh0stRAT, CyberSpike, Dumpling RAT, and DarkRAT. The malware appears in reporting as a commodity/open-source or cracked RAT used in multi-stage intrusion chains and malware delivery ecosystems.

BitRAT has been observed or referenced in campaigns involving multiple threat actors and delivery chains. Reporting cited it among the RATs used by TAG-144 / Blind Eagle, which has targeted Colombian government entities and other organizations in South America via spearphishing and staged payload delivery. Kaspersky also reported BlindEagle rotating among open-source RATs including BitRAT. BitRAT was additionally reported as a companion payload in campaigns delivering Rhadamanthys, and historical reporting on the Blister loader noted a campaign that reportedly dropped Cobalt Strike and BitRAT. Check Point also listed BitRAT among malware families delivered by the dotRunpeX injector.

Infrastructure and detection reporting directly tie BitRAT to command-and-control activity. As of 16 June 2026, Censys had confirmed one BitRAT command-and-control host, tracked as THREAT-0162. Censys assessed inherited DCRAT TLS certificate metadata as the most reliable detection signal across the broader AsyncRAT family, including BitRAT. The reported family-wide indicator is self-signed TLS certificates on non-standard ports with subject/issuer patterns such as "O=<Name> By <author>, L=SH, C=CN," with variant names and builder handles appearing in certificate fields. A Nuclei template exists for BitRAT C2 detection at ssl/c2/bitrat-c2.yaml, and public references also point to Censys hunting queries for BitRAT infrastructure.

BitRAT is also referenced in underground-market advertising as an "advanced Windows RAT," further supporting its role as a commodity Windows remote administration malware family. High-confidence content does not provide additional verified technical details here on its internal modules, persistence, or specific data-theft functions beyond its classification and observed use as a RAT.

Reported operators

Threat actors

1 named in public reporting
APT-C-36

TAG-144 leverages a range of commodity remote access trojans (RATs), including AsyncRAT, REMCOS RAT, DcRAT, njRAT, LimeRAT, QuasarRAT, BitRAT, and a Quasar variant known as BlotchyQuasar.

MITRE ATT&CK

BitRAT in ATT&CK

6 distinct techniques

Reporting

Research mentioning BitRAT

Jul 17
Levelblue Spiderlabs

Still Circling: Blind Eagle's Toolkit Keeps Evolving

Blind Eagle, also tracked as TAG-144, APT-C-36, and linked by some researchers to Red Akodon, continued targeting organizations across South America with a sustained emphasis on Colombian government entities at the local, municipal, and federal levels. Researchers described multi-stage intrusion chains using spearphishing, including compromised Colombian government email accounts, to deliver commodity and cracked remote access trojans through exposed Apache staging servers, dynamic DNS infrastructure, and legitimate internet services used for payload staging. The group has remained active since at least 2018, blending credential theft, financial crime, and surveillance-oriented collection against public-sector targets. Recent activity shows the actor refining rather than replacing its established toolkit. Investigators observed VBScript-to-PowerShell delivery chains, steganography to conceal payloads in image files, a new JavaScript stage with custom AES-based string obfuscation, an AutoIt3 RunPE loader fetched from raw.githubusercontent.com, and repeated use of the "Photo Studio" persistence disguise. The most significant upgrade was a new AsyncRAT variant, JC-46, which adds WNF-based process injection, custom Base28 encoding, HVNC support for banking fraud, browser profile cloning, and a bypass for Chrome App-Bound Encryption v20, while the group continued reusing VPN-linked command-and-control infrastructure and familiar dynamic DNS patterns.

Aug 26
Recorded Future

TAG-144’s Persistent Grip on South American Organizations

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.