Last seven days
- First activity
- Aug 26, 2026
- Last activity
- Sep 1, 2026
- Feed role
- C2
- Host form
- 12 IP / 72 hostnames
Neptune RAT is a remote access trojan with at least two major versions, V1 and V2.
Profile source: Mallory opens in a new tabNeptune RAT
Neptune RAT is a remote access trojan with at least two major versions, V1 and V2. High-confidence reporting indicates Neptune RAT V1 has substantial technical overlap with XWORM and is most likely derived from it rather than independently developed. Researchers observed Neptune RAT samples triggering detections originally written for XWORM, and reverse engineering found closely matching initialization flow, configuration handling, and persistence logic.
Neptune RAT V1 loads configuration at the start of execution and stores configuration values in a single class of static strings. Its configuration strings, except the mutex, are AES-encrypted and Base64-encoded. Neptune RAT V1 and XWORM share a distinctive crypto routine in which the mutex is MD5-hashed and duplicated to form a 32-byte AES key, with AES used in ECB mode. This overlap reportedly caused Neptune RAT V1 configurations to be conflated with XWORM configurations in tracking systems.
Reported persistence mechanisms for Neptune RAT V1 include Task Scheduler, registry entries, and the startup folder. The malware also includes clipper-related logic: Neptune RAT V1 and XWORM reportedly use identical regular expressions targeting BTC, ETH, and TRC cryptocurrency wallets. Neptune RAT V1 specifically targets legacy Bitcoin addresses and largely ignores Bech32 addresses.
Open-source analysis cited in the content identified GitHub repositories that partially reconstruct Neptune RAT development history. A repository referenced as MasonGroup/NeptuneRatV1 is described as a fork of the V1 builder, with activity concentrated in early December 2024 and references to a Discord server named FreemasonryTM. A separate NeptuneRatV2 repository, first committed on February 22, 2025, is described as a trial version of a newer builder. Neptune RAT V2 appears to be a major rewrite or extensive refactor: its builder is described as more polished, its code flow differs from V1, variable names are not obfuscated, and configuration data is stored as plaintext strings in a Settings class rather than encrypted.
The content does not provide a confirmed threat actor attribution for Neptune RAT itself, but it does state that Neptune RAT V1 was linked to the investigated campaign and that ongoing development of the original Neptune RAT repository continued after the public forks, with the original repository later made private. The content also notes that SHA-256 hashes exist for samples labeled Neptune V1 RAT and Neptune V2 RAT, but the specific hashes are not reproduced in the provided material.
C2 tracking
Derp observations, rolling seven-day window
Samples
4be813732123a8108707d7dbbb989b016d48c559ffb7ccfd142ac0b2cb692b36 7f21fe664583e9bb52f311cf8917a4523eff80d1ee294ea777a9e28cbbfcab97 c4a71aade38a379c7547ee2dca7f251b466d72ac7dcd05b15eae7c6824ac2e76 dcd46f1fbeeebd9dde764315469b874aeed7bbe043887ff2cd50a88b97e917b5 eb323fb7aee769b04a8f0f89d08592e2ab9750879a24f75b6c529af55a612d1c 5447e1e7ed3521263b9567fd579a31c483c6adc04127fcd6bc1d6c8b2864cbba 555a32da8b3452d98988b64302a05a7d90d3441d3b0cf6c3be852ae5eae9fdcd 5f63db931294949f97206e53298a57b302b84f58d82bbaec9a535ad52c339206 d5ca90a68e8ef8e00a35dfa7a23880124415265640bc3d129f80c79663f24fde e060c0af464ce7ec1d74ce8246814e2fb184ba831a446cb9198f0ee1f4486bd1 Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.