Last seven days
- First activity
- Aug 24, 2026
- Last activity
- Aug 24, 2026
- Feed role
- C2
- Host form
- 1 IP / 0 hostnames
LimeRAT is a Windows-based remote access trojan written in Visual Basic .NET and commonly described as a modified variant of njRAT.
Profile source: Mallory opens in a new tabLimeRAT
LimeRAT is a Windows-based remote access trojan written in Visual Basic .NET and commonly described as a modified variant of njRAT. It is used as a commodity RAT in multi-stage intrusion chains and has appeared in campaigns targeting government and private-sector organizations, including activity focused on Colombia and broader South America. It has also been associated with operations linked to Blind Eagle/APT-C-36/TAG-144, although attribution is not uniform across all observed LimeRAT deployments.
LimeRAT supports typical RAT functionality including remote control, file management, credential theft, keylogging, screenshot or remote desktop access, downloading additional payloads, and persistence. Reported variants and builder features also include encrypted client-server communications, plugin-based extensibility, cryptocurrency theft, DDoS capability, and optional ransomware and mining components. In observed intrusions, LimeRAT has been delivered as a final payload through script-heavy loaders that use VBScript, batch files, PowerShell, reflective loading, and process injection into legitimate Windows or .NET processes to evade detection. Persistence has been established through mechanisms including Run keys, scheduled tasks, and startup-related execution paths.
Observed delivery vectors include spearphishing and phishing emails with geopolitical, judicial, banking, invoice, or COVID-themed lures; malicious Office documents with VBA macros; compressed archives and ISO disk images; and abuse of legitimate hosting or collaboration platforms for staging additional payloads. Campaigns have used multi-stage chains in which an initial script or document selects a compatible .NET payload and then launches LimeRAT in memory or under a disguised executable name.
LimeRAT has been distributed alongside or interchangeably with other commodity RATs such as AsyncRAT, RevengeRAT, QuasarRAT, BitRAT, NanoCore RAT, Warzone RAT, and njRAT, indicating its role in flexible malware delivery ecosystems rather than a single exclusive operator toolkit. Its repeated use in Latin America-focused phishing and surveillance-oriented campaigns, especially against Colombian entities, makes it notable both as commodity malware and as a recurring component in regional threat activity.
C2 tracking
Derp observations, rolling seven-day window
Samples
Reported operators
Furthermore, the RAT used in this scenario was Lime-RAT, a modified version of njRAT.
In some cases, the final stage PowerShell script contained up to seven various RATs. These are typically NjRat, BitRat, Nanocore RAT, QuasarRat, LimeRat, and Warzone.
MITRE ATT&CK
Reporting
Blind Eagle, also tracked as TAG-144, APT-C-36, and linked by some researchers to Red Akodon, continued targeting organizations across South America with a sustained emphasis on Colombian government entities at the local, municipal, and federal levels. Researchers described multi-stage intrusion chains using spearphishing, including compromised Colombian government email accounts, to deliver commodity and cracked remote access trojans through exposed Apache staging servers, dynamic DNS infrastructure, and legitimate internet services used for payload staging. The group has remained active since at least 2018, blending credential theft, financial crime, and surveillance-oriented collection against public-sector targets. Recent activity shows the actor refining rather than replacing its established toolkit. Investigators observed VBScript-to-PowerShell delivery chains, steganography to conceal payloads in image files, a new JavaScript stage with custom AES-based string obfuscation, an AutoIt3 RunPE loader fetched from raw.githubusercontent.com, and repeated use of the "Photo Studio" persistence disguise. The most significant upgrade was a new AsyncRAT variant, JC-46, which adds WNF-based process injection, custom Base28 encoding, HVNC support for banking fraud, browser profile cloning, and a bypass for Chrome App-Bound Encryption v20, while the group continued reusing VPN-linked command-and-control infrastructure and familiar dynamic DNS patterns.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.