Skip to content

LimeRAT

LimeRAT is a Windows-based remote access trojan written in Visual Basic .NET and commonly described as a modified variant of njRAT.

Profile source: Mallory opens in a new tab

LimeRAT

Family profile

LimeRAT is a Windows-based remote access trojan written in Visual Basic .NET and commonly described as a modified variant of njRAT. It is used as a commodity RAT in multi-stage intrusion chains and has appeared in campaigns targeting government and private-sector organizations, including activity focused on Colombia and broader South America. It has also been associated with operations linked to Blind Eagle/APT-C-36/TAG-144, although attribution is not uniform across all observed LimeRAT deployments.

LimeRAT supports typical RAT functionality including remote control, file management, credential theft, keylogging, screenshot or remote desktop access, downloading additional payloads, and persistence. Reported variants and builder features also include encrypted client-server communications, plugin-based extensibility, cryptocurrency theft, DDoS capability, and optional ransomware and mining components. In observed intrusions, LimeRAT has been delivered as a final payload through script-heavy loaders that use VBScript, batch files, PowerShell, reflective loading, and process injection into legitimate Windows or .NET processes to evade detection. Persistence has been established through mechanisms including Run keys, scheduled tasks, and startup-related execution paths.

Observed delivery vectors include spearphishing and phishing emails with geopolitical, judicial, banking, invoice, or COVID-themed lures; malicious Office documents with VBA macros; compressed archives and ISO disk images; and abuse of legitimate hosting or collaboration platforms for staging additional payloads. Campaigns have used multi-stage chains in which an initial script or document selects a compatible .NET payload and then launches LimeRAT in memory or under a disguised executable name.

LimeRAT has been distributed alongside or interchangeably with other commodity RATs such as AsyncRAT, RevengeRAT, QuasarRAT, BitRAT, NanoCore RAT, Warzone RAT, and njRAT, indicating its role in flexible malware delivery ecosystems rather than a single exclusive operator toolkit. Its repeated use in Latin America-focused phishing and surveillance-oriented campaigns, especially against Colombian entities, makes it notable both as commodity malware and as a recurring component in regional threat activity.

Capabilities

  • Credential Theft
  • Crypto Theft
  • Ddos
  • Defense Evasion
  • Exfiltration
  • Keylogging
  • Persistence
  • Post Exploitation
  • Process Injection

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 24, 2026
Last activity
Aug 24, 2026
Feed role
C2
Host form
1 IP / 0 hostnames

Leading locations

  • DE1

Leading providers

  • Lowhosting services of Davide Gennari1

Infrastructure traits

  • Hosting 1

Samples

Recent associated samples

Reported operators

Threat actors

2 named in public reporting
APT-C-36

Furthermore, the RAT used in this scenario was Lime-RAT, a modified version of njRAT.

Water Basilisk

In some cases, the final stage PowerShell script contained up to seven various RATs. These are typically NjRat, BitRat, Nanocore RAT, QuasarRat, LimeRat, and Warzone.

MITRE ATT&CK

LimeRAT in ATT&CK

37 distinct techniques

Reporting

Research mentioning LimeRAT

Jul 17
Levelblue Spiderlabs

Still Circling: Blind Eagle's Toolkit Keeps Evolving

Blind Eagle, also tracked as TAG-144, APT-C-36, and linked by some researchers to Red Akodon, continued targeting organizations across South America with a sustained emphasis on Colombian government entities at the local, municipal, and federal levels. Researchers described multi-stage intrusion chains using spearphishing, including compromised Colombian government email accounts, to deliver commodity and cracked remote access trojans through exposed Apache staging servers, dynamic DNS infrastructure, and legitimate internet services used for payload staging. The group has remained active since at least 2018, blending credential theft, financial crime, and surveillance-oriented collection against public-sector targets. Recent activity shows the actor refining rather than replacing its established toolkit. Investigators observed VBScript-to-PowerShell delivery chains, steganography to conceal payloads in image files, a new JavaScript stage with custom AES-based string obfuscation, an AutoIt3 RunPE loader fetched from raw.githubusercontent.com, and repeated use of the "Photo Studio" persistence disguise. The most significant upgrade was a new AsyncRAT variant, JC-46, which adds WNF-based process injection, custom Base28 encoding, HVNC support for banking fraud, browser profile cloning, and a bypass for Chrome App-Bound Encryption v20, while the group continued reusing VPN-linked command-and-control infrastructure and familiar dynamic DNS patterns.

Aug 26
Recorded Future

TAG-144’s Persistent Grip on South American Organizations

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.