Last seven days
- First activity
- Sep 3, 2026
- Last activity
- Sep 9, 2026
- Feed role
- C2
- Host form
- 5 IP / 23 hostnames
Neptune RAT is a remote access trojan with at least two major versions, V1 and V2.
Profile source: Mallory opens in a new tabNeptune RAT
Neptune RAT is a remote access trojan with at least two major versions, V1 and V2. High-confidence reporting indicates Neptune RAT V1 has substantial technical overlap with XWORM and is most likely derived from it rather than independently developed. Researchers observed Neptune RAT samples triggering detections originally written for XWORM, and reverse engineering found closely matching initialization flow, configuration handling, and persistence logic.
Neptune RAT V1 loads configuration at the start of execution and stores configuration values in a single class of static strings. Its configuration strings, except the mutex, are AES-encrypted and Base64-encoded. Neptune RAT V1 and XWORM share a distinctive crypto routine in which the mutex is MD5-hashed and duplicated to form a 32-byte AES key, with AES used in ECB mode. This overlap reportedly caused Neptune RAT V1 configurations to be conflated with XWORM configurations in tracking systems.
Reported persistence mechanisms for Neptune RAT V1 include Task Scheduler, registry entries, and the startup folder. The malware also includes clipper-related logic: Neptune RAT V1 and XWORM reportedly use identical regular expressions targeting BTC, ETH, and TRC cryptocurrency wallets. Neptune RAT V1 specifically targets legacy Bitcoin addresses and largely ignores Bech32 addresses.
Open-source analysis cited in the content identified GitHub repositories that partially reconstruct Neptune RAT development history. A repository referenced as MasonGroup/NeptuneRatV1 is described as a fork of the V1 builder, with activity concentrated in early December 2024 and references to a Discord server named FreemasonryTM. A separate NeptuneRatV2 repository, first committed on February 22, 2025, is described as a trial version of a newer builder. Neptune RAT V2 appears to be a major rewrite or extensive refactor: its builder is described as more polished, its code flow differs from V1, variable names are not obfuscated, and configuration data is stored as plaintext strings in a Settings class rather than encrypted.
The content does not provide a confirmed threat actor attribution for Neptune RAT itself, but it does state that Neptune RAT V1 was linked to the investigated campaign and that ongoing development of the original Neptune RAT repository continued after the public forks, with the original repository later made private. The content also notes that SHA-256 hashes exist for samples labeled Neptune V1 RAT and Neptune V2 RAT, but the specific hashes are not reproduced in the provided material.
C2 tracking
Derp observations, rolling seven-day window
Samples
1f561b6fbff3367b6904297b380dad08f811a45eba24984bf741deb80baf827b 291a1d270ed54ae2e6484508b265598ce1d5023764c78819d79c65e9ae3fab33 43cc08aca48880f14350605bb260175ab9a8161f430f00dd6093d446d7294fcf 72dc109cdcff33a0267a63da9ac37c2763b916bae508ff2459f460c13a3c83cc 88df1be6306b7551eb981cadcb3158e7213f56bef7860e45259862bfc6c9e014 378d097c7adb457227160e62a62174e83b6ccba9f3ffa7d447061c5a89added7 4224e6202b6b7b432a7dc889a212d9615a5e7837787667b44e3b438cb4ca7c80 43d9fad15afddd4c2d0a0b91d84ae0be55375de4e840b4fb5adf064c641c2dbb e23eb2ea7a1f8ea6e390b48f7c30e456b20c0661000cb63a3b04d29307b42a70 f400745eda95e87c80053e89803f602861d965ac426f0bba4bd85d0280dbeddb Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.