Last seven days
- First activity
- Aug 1, 2026
- Last activity
- Aug 8, 2026
- Feed role
- C2 / Distribution
- Host form
- 36 IP / 39 hostnames
njRAT, also known as Bladabindi and NJW0rm, is a commodity Windows remote access Trojan written for the .NET ecosystem and widely used by cybercriminal and espionage operators.
Profile source: Mallory opens in a new tabnjRAT
njRAT, also known as Bladabindi and NJW0rm, is a commodity Windows remote access Trojan written for the .NET ecosystem and widely used by cybercriminal and espionage operators. It provides persistent unauthorized remote access and supports interactive surveillance and follow-on payload delivery. Documented capabilities include keylogging, screenshot capture, webcam access, microphone control, download-and-execute of additional malware, registry querying and modification, current-user enumeration, camera detection, removable-drive detection, and process-injection-related behavior. Analysis of staged infections has also shown socket-based data transmission and heavy use of obfuscation across intermediate loaders and scripts.
Observed delivery chains include spearphishing and phishing lures using weaponized Office documents with macros or exploit documents, as well as staged script-based loaders that retrieve additional components from paste or text-hosting services. njRAT has also appeared in broader malware distribution ecosystems involving crypters and commodity loaders, and has been distributed by actors using email campaigns and socially engineered lures. In some campaigns it has been dropped alongside or instead of other commodity RATs such as AsyncRAT, Remcos, and XWorm.
njRAT has been used by multiple threat actors and intrusion sets, including activity associated with Aquatic Panda, TA558, Gamaredon, and Transparent Tribe-related operations. It has been observed in campaigns targeting government, diplomatic, military, and regional victims, including Indian and Ukrainian targets, as well as in more general cybercriminal operations. Its longevity, low barrier to acquisition, and broad surveillance feature set have made it a recurring tool in both opportunistic and targeted intrusions.
C2 tracking
Derp observations, rolling seven-day window
Samples
72faffb7f0ad058f27ed60bb2275f04ef0100b85783289b8f05de07a8e50beac d917649cc7fad73bc15280912d000d5c7852792f5f8450f5bed49715e5506502 dcd8a11898d88fa582327920ed56cf2b7678350b1944df8bf927a8db09cc52a5 ed06ad644bb9c18902445011763d6aeaa220dfa902137669acb111e59703c17c f4c6cf44426a4fc43c90344d870707a0bfdd07aa46ce66b5b84c8dc46e056ded 16b5474f30ebd15e96ae71cdca120127c1c2212c2d04386dad168be90a5b1cb7 2c0bfd9f625ee02087858edfa79c243c2fd1c75cd1c45a579970273df8502e56 6be7a1d1f1b694636c0445da41aefdd1841abb76e6b20c174c3721859fb4ef0f abe4ced27b1c19ac49269c469d30855efa54b58819a6a4ee774eba7e367a33b3 da456682afc04a8ea4976611bc3ff2ef1962dd239aa524580520bfecef92b80a Reported operators
the payloads riding on top of them (NjRAT, AsyncRAT, LimeRAT) have barely changed in years
The group has been observed using widely-available tools such as the Remote Access Trojan (RAT) called βnjRATβ...
Aquatic Panda has acquired and used njRAT in its operations.
This site is likely operated by the same actor(s) that carried out the previously discussed attacks on Indian embassy officials based on shared C&C infrastructure... lure Indian military officials into becoming infected with MSIL/Crimson, njRAT, and possibly other malicious tools.
While the actor favors VenomRAT, TA558 also distributes other commodity malware including njRAT, Remcos RAT, and recently XWorm and PDQ Connect.
The top 10 of the RATs used in Nigerian BEC scams is formed by NetWire, DarkComet, NanoCore, LuminosityLink, Remcos, ImminentMonitor, NJRat, Quasar, Adwind, and Hworm.
"However, the ultimate malware payload in this case is njRat, another well-known RAT tool."
"Some of the payloads identified for campaign 2... included... RAT Bladabindi"
This article presents a reverse engineering analysis of njRAT v0.7. njRAT, also known as Bladabindi, is a remote access tool (RAT) with user interface which allows the operator to control the victimβs computer.
Exploited software
MITRE ATT&CK
Reporting
Blind Eagle, also tracked as TAG-144, APT-C-36, and linked by some researchers to Red Akodon, continued targeting organizations across South America with a sustained emphasis on Colombian government entities at the local, municipal, and federal levels. Researchers described multi-stage intrusion chains using spearphishing, including compromised Colombian government email accounts, to deliver commodity and cracked remote access trojans through exposed Apache staging servers, dynamic DNS infrastructure, and legitimate internet services used for payload staging. The group has remained active since at least 2018, blending credential theft, financial crime, and surveillance-oriented collection against public-sector targets. Recent activity shows the actor refining rather than replacing its established toolkit. Investigators observed VBScript-to-PowerShell delivery chains, steganography to conceal payloads in image files, a new JavaScript stage with custom AES-based string obfuscation, an AutoIt3 RunPE loader fetched from raw.githubusercontent.com, and repeated use of the "Photo Studio" persistence disguise. The most significant upgrade was a new AsyncRAT variant, JC-46, which adds WNF-based process injection, custom Base28 encoding, HVNC support for banking fraud, browser profile cloning, and a bypass for Chrome App-Bound Encryption v20, while the group continued reusing VPN-linked command-and-control infrastructure and familiar dynamic DNS patterns.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.