Last seven days
- First activity
- Aug 22, 2026
- Last activity
- Aug 29, 2026
- Feed role
- C2 / Distribution
- Host form
- 125 IP / 144 hostnames
njRAT, also known as Bladabindi, LV, and Njw0rm, is a Windows remote-access trojan.
Profile source: Mallory opens in a new tabnjRAT
njRAT, also known as Bladabindi, LV, and Njw0rm, is a Windows remote-access trojan. It provides remote access to compromised hosts and has been used by multiple threat actors, including APT-C-36 (Blind Eagle), Aquatic Panda, and operators associated with Operation Spalax. Known functionality includes capturing screenshots, enumerating the current user and running processes, stealing passwords saved in web browsers, and transferring stolen data over HTTP-based command-and-control communications. njRAT can establish persistence through Windows Registry autostart mechanisms and Startup-folder shortcuts, and it has executed PowerShell commands through its persistence configuration. It also uses Base64 encoding for command-and-control traffic and has used AutoIt to compile its payload and main script into a single executable after delivery.
C2 tracking
Derp observations, rolling seven-day window
Samples
2fcad226b17131da4274e1b9f8f31359bdd325c9568665f08fd1f6c5d06a23ce 30daba44a4a25ff5750508613f897057a55337458f19b562e2ed1172c77e626b 4e5cc8cb98584335400d00f0a0803c3e0202761f3fbe50bcab3858a80df255e1 7126b9932dc0cdfe751340edfa7c4a14b69262eb1afd0530e6d1fdb2e25986dd 73ddf0df4e9e3866511ef9eae421b11615b81491d0db1d4a7ed19441e368ecef 3ac88750fa45ff75a48bdc047c9e634428ba56f283c0dedc7120a3189150fc2a 9ce61de4592e2bbca1d28acc749ccba1fee81b344658bc1570235a93c927b339 d56adcfcce1faf9bf4daf817bf3fb7489f86198e14477e28aa787d015e8de2e0 d94975ee4535cdb2cfb976f6a1357c1dad06539b87a9d74b35eff23b63deafaa ed9c2fad37ee2a20561c9e5584e5d48d47a73ab5f14f9b51e2676cdf07389d47 Reported operators
“In the past, we have observed that APT-C-36 makes use of RATs such as: njRAT ...”
к доменам хак-группы обращались более 31 000 образцов вредоносов, включая Quasar RAT, AsyncRAT, DCRat, NanoCore, Remcos RAT и njRAT
Aquatic Panda has acquired and used njRAT in its operations.
This group continued to use a variety of malware payloads including the addition of njRAT and Ozone RAT.
ESRC에서는 해당 악성코드 (njRAT) 와 관련된 상세 내용과 인텔리전스 리포트를 '쓰렛 인사이드(Threat Inside)' 서비스를 통해 자세히 제공할 예정입니다.
Summary njRAT (Bladabindi) is a .NET RAT (Remote Access Trojan) that allows attackers to take control of an infected machine.
Cisco Talos has observed a new malware campaign delivering commodity RATs, including njRAT and AsyncRAT.
CTU analysis revealed that the LV ransomware is not a distinct ransomware family; it is repurposed REvil ransomware.
In some cases, the final stage PowerShell script contained up to seven various RATs. These are typically NjRat, BitRat, Nanocore RAT, QuasarRat, LimeRat, and Warzone.
njRAT, also known as Bladabindi, is the most active and prevalent remote access trojan... Since the leak of source code 2013, njRAT has become widely adopted by cybercriminals and APT actors including Gorgon Group and APT41.
njRAT, also known as Bladabindi, is the most active and prevalent remote access trojan... Since the leak of source code 2013, njRAT has become widely adopted by cybercriminals and APT actors including Gorgon Group and APT41.
This blog is all about njRAT that has been found to be hosted on paste.ee site... njRAT also known as ‘ Bladabindi ’ or ‘ njw0rm ’ is a Remote Access Trojan (RAT)...
This blog is all about njRAT that has been found to be hosted on paste.ee site... njRAT also known as ‘ Bladabindi ’ or ‘ njw0rm ’ is a Remote Access Trojan (RAT)...
This blog is all about njRAT that has been found to be hosted on paste.ee site... njRAT also known as ‘ Bladabindi ’ or ‘ njw0rm ’ is a Remote Access Trojan (RAT)...
This blog is all about njRAT that has been found to be hosted on paste.ee site... njRAT also known as ‘ Bladabindi ’ or ‘ njw0rm ’ is a Remote Access Trojan (RAT)...
This blog is all about njRAT that has been found to be hosted on paste.ee site... njRAT also known as ‘ Bladabindi ’ or ‘ njw0rm ’ is a Remote Access Trojan (RAT)...
Sphinx reportedly uses the watering hole technique via social media sites to deliver its payloads — mainly a customized version of njRAT.
This blog is all about njRAT that has been found to be hosted on paste.ee site... njRAT also known as ‘ Bladabindi ’ or ‘ njw0rm ’ is a Remote Access Trojan (RAT)...
This blog is all about njRAT that has been found to be hosted on paste.ee site... njRAT also known as ‘ Bladabindi ’ or ‘ njw0rm ’ is a Remote Access Trojan (RAT)...
This blog is all about njRAT that has been found to be hosted on paste.ee site... njRAT also known as ‘ Bladabindi ’ or ‘ njw0rm ’ is a Remote Access Trojan (RAT)...
We discovered an active campaign ongoing since at least mid-2022 which uses Middle Eastern geopolitical-themed lures to distribute NjRAT (also known as Bladabindi) to infect victims across the Middle East and North Africa.
This group occasionally deployed publicly available malware for Windows, including NJRat and HWorm, commonly used in the region.
Sphinx reportedly uses the watering hole technique via social media sites to deliver its payloads — mainly a customized version of njRAT.
The group has been observed using widely-available tools such as the Remote Access Trojan (RAT) called “njRAT”...
The top 10 of the RATs used in Nigerian BEC scams is formed by NetWire, DarkComet, NanoCore, LuminosityLink, Remcos, ImminentMonitor, NJRat, Quasar, Adwind, and Hworm.
This article presents a reverse engineering analysis of njRAT v0.7. njRAT, also known as Bladabindi, is a remote access tool (RAT) with user interface which allows the operator to control the victim’s computer.
Exploited software
MITRE ATT&CK
Reporting
Blind Eagle, also tracked as TAG-144, APT-C-36, and linked by some researchers to Red Akodon, continued targeting organizations across South America with a sustained emphasis on Colombian government entities at the local, municipal, and federal levels. Researchers described multi-stage intrusion chains using spearphishing, including compromised Colombian government email accounts, to deliver commodity and cracked remote access trojans through exposed Apache staging servers, dynamic DNS infrastructure, and legitimate internet services used for payload staging. The group has remained active since at least 2018, blending credential theft, financial crime, and surveillance-oriented collection against public-sector targets. Recent activity shows the actor refining rather than replacing its established toolkit. Investigators observed VBScript-to-PowerShell delivery chains, steganography to conceal payloads in image files, a new JavaScript stage with custom AES-based string obfuscation, an AutoIt3 RunPE loader fetched from raw.githubusercontent.com, and repeated use of the "Photo Studio" persistence disguise. The most significant upgrade was a new AsyncRAT variant, JC-46, which adds WNF-based process injection, custom Base28 encoding, HVNC support for banking fraud, browser profile cloning, and a bypass for Chrome App-Bound Encryption v20, while the group continued reusing VPN-linked command-and-control infrastructure and familiar dynamic DNS patterns.
Multiple cyber-espionage operations targeted الفلسطينيين, activists, and organizations in the Palestinian territories with politically themed phishing lures and fake documents that delivered custom backdoors including Micropsia, Spark, Pierogi, and Scote. Reporting from Cisco Talos, Cybereason, and Palo Alto Networks links the activity to long-running Middle East-focused threat actors Arid Viper and MoleRATs (also known as the Gaza Cybergang), which repeatedly used Arabic-language decoys tied to regional politics, social-engineering archives hosted on services such as Dropbox and Egnyte, malicious RTF and Word files, and self-extracting executables to infect victims. The malware families provided persistent remote access and espionage capabilities including host reconnaissance, command execution, keylogging, screenshot capture, audio recording, file transfer, and HTTP-based command-and-control. Researchers said the operators also used evasion and targeting checks such as security-product discovery, Arabic language or keyboard validation, packers, and abuse of third-party platforms including Pastebin, Google+, and URL shorteners to hide infrastructure and retrieve C2 data. Across the campaigns, analysts observed largely consistent tradecraft over several years, indicating sustained intelligence collection against Palestinian political and civil-society targets despite repeated public exposure.
Invicta Stealer is being spread through phishing emails that impersonate GoDaddy refund invoices, using an infection chain that begins with a malicious HTML attachment and progresses through ZIP, LNK, HTA, and PowerShell stages before installing the information-stealing malware. Researchers said the malware’s developer has promoted the family on Telegram, YouTube, and GitHub, including a free builder that appears to have lowered the barrier to entry for other threat actors and increased the stealer’s circulation. Once executed by the victim, Invicta Stealer gathers extensive host and user data, including browser information, Discord data, cryptocurrency wallet contents, Steam and KeePass artifacts, installed application details, and files from Desktop and Documents, then compresses and exfiltrates the data to a Discord webhook or other command-and-control endpoint. The campaign aligns with common user execution tradecraft in phishing-led intrusions, and the malware also uses anti-analysis features such as encrypted strings, syscalls, and multithreading while collecting system and application context from infected machines.
Elastic Endpoint Security added kernel-driver-derived file and registry telemetry to detect access to sensitive credential stores, including browser data, Windows SAM and LSA secrets, cached domain credentials, credential files, and Windows Credential Manager. Its behavior protections can block high-confidence credential-theft activity associated with tools and malware such as Mimikatz, LaZagne, AgentTesla, FormBook, and Poulight Stealer; KQL and EQL hunting can also identify processes opening multiple sensitive stores or SMB access following a network logon. Attackers commonly extract saved browser usernames, passwords, cookies, and session tokens from stores such as Chrome’s Login Data and Firefox’s key3.db, key4.db, and logins.json. They also dump Windows LSA secrets and cached domain credentials using utilities including Mimikatz, reg save, Impacket secretsdump.py, CrackMapExec, and gsecdump. Cached Windows credentials are generally stored as DCC2/MS-Cache v2 hashes and require offline cracking rather than pass-the-hash, while Linux Active Directory integrations may retain cached credentials in SSSD or Quest database files.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.