Skip to content

njRAT

njRAT, also known as Bladabindi, LV, and Njw0rm, is a Windows remote-access trojan.

Profile source: Mallory opens in a new tab

njRAT

Family profile

njRAT, also known as Bladabindi, LV, and Njw0rm, is a Windows remote-access trojan. It provides remote access to compromised hosts and has been used by multiple threat actors, including APT-C-36 (Blind Eagle), Aquatic Panda, and operators associated with Operation Spalax. Known functionality includes capturing screenshots, enumerating the current user and running processes, stealing passwords saved in web browsers, and transferring stolen data over HTTP-based command-and-control communications. njRAT can establish persistence through Windows Registry autostart mechanisms and Startup-folder shortcuts, and it has executed PowerShell commands through its persistence configuration. It also uses Base64 encoding for command-and-control traffic and has used AutoIt to compile its payload and main script into a single executable after delivery.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Persistence
  • Post Exploitation
  • Reconnaissance

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 22, 2026
Last activity
Aug 29, 2026
Feed role
C2 / Distribution
Host form
125 IP / 144 hostnames

Leading locations

  • US51
  • CN43
  • DE27
  • GB18
  • NL15
  • HK12
  • RU10
  • FR7
  • KR7
  • SG5
  • TH5
  • LU4

Leading providers

  • Cloudflare, Inc.16
  • Hangzhou Alibaba Advertising Co.,Ltd.15
  • OOO GETWIFI12
  • Oracle Corporation10
  • FEMO IT SOLUTIONS LIMITED9
  • CTG Server Limited7

Infrastructure traits

  • Hosting 178
  • Anycast 18

Samples

Recent associated samples

Reported operators

Threat actors

26 named in public reporting
APT-C-36

“In the past, we have observed that APT-C-36 makes use of RATs such as: njRAT ...”

Sable Squirrel

к доменам хак-группы обращались более 31 000 образцов вредоносов, включая Quasar RAT, AsyncRAT, DCRat, NanoCore, Remcos RAT и njRAT

Earth Lusca

Aquatic Panda has acquired and used njRAT in its operations.

TA558

This group continued to use a variety of malware payloads including the addition of njRAT and Ozone RAT.

Lazarus

ESRC에서는 해당 악성코드 (njRAT) 와 관련된 상세 내용과 인텔리전스 리포트를 '쓰렛 인사이드(Threat Inside)' 서비스를 통해 자세히 제공할 예정입니다.

Transparent Tribe

Summary njRAT (Bladabindi) is a .NET RAT (Remote Access Trojan) that allows attackers to take control of an infected machine.

Aggah

Cisco Talos has observed a new malware campaign delivering commodity RATs, including njRAT and AsyncRAT.

GOLD NORTHFIELD

CTU analysis revealed that the LV ransomware is not a distinct ransomware family; it is repurposed REvil ransomware.

Water Basilisk

In some cases, the final stage PowerShell script contained up to seven various RATs. These are typically NjRat, BitRat, Nanocore RAT, QuasarRat, LimeRat, and Warzone.

Gorgon Group

njRAT, also known as Bladabindi, is the most active and prevalent remote access trojan... Since the leak of source code 2013, njRAT has become widely adopted by cybercriminals and APT actors including Gorgon Group and APT41.

APT41

njRAT, also known as Bladabindi, is the most active and prevalent remote access trojan... Since the leak of source code 2013, njRAT has become widely adopted by cybercriminals and APT actors including Gorgon Group and APT41.

RevengeHotels

This blog is all about njRAT that has been found to be hosted on paste.ee site... njRAT also known as ‘ Bladabindi ’ or ‘ njw0rm ’ is a Remote Access Trojan (RAT)...

Group5

This blog is all about njRAT that has been found to be hosted on paste.ee site... njRAT also known as ‘ Bladabindi ’ or ‘ njw0rm ’ is a Remote Access Trojan (RAT)...

Molerats

This blog is all about njRAT that has been found to be hosted on paste.ee site... njRAT also known as ‘ Bladabindi ’ or ‘ njw0rm ’ is a Remote Access Trojan (RAT)...

RedAlpha

This blog is all about njRAT that has been found to be hosted on paste.ee site... njRAT also known as ‘ Bladabindi ’ or ‘ njw0rm ’ is a Remote Access Trojan (RAT)...

RATicate

This blog is all about njRAT that has been found to be hosted on paste.ee site... njRAT also known as ‘ Bladabindi ’ or ‘ njw0rm ’ is a Remote Access Trojan (RAT)...

Sphinx

Sphinx reportedly uses the watering hole technique via social media sites to deliver its payloads — mainly a customized version of njRAT.

Pat-Bear

This blog is all about njRAT that has been found to be hosted on paste.ee site... njRAT also known as ‘ Bladabindi ’ or ‘ njw0rm ’ is a Remote Access Trojan (RAT)...

Goldmouse

This blog is all about njRAT that has been found to be hosted on paste.ee site... njRAT also known as ‘ Bladabindi ’ or ‘ njw0rm ’ is a Remote Access Trojan (RAT)...

Operation Commando

This blog is all about njRAT that has been found to be hosted on paste.ee site... njRAT also known as ‘ Bladabindi ’ or ‘ njw0rm ’ is a Remote Access Trojan (RAT)...

Earth Bogle

We discovered an active campaign ongoing since at least mid-2022 which uses Middle Eastern geopolitical-themed lures to distribute NjRAT (also known as Bladabindi) to infect victims across the Middle East and North Africa.

APT-C-15

Sphinx reportedly uses the watering hole technique via social media sites to deliver its payloads — mainly a customized version of njRAT.

Gamaredon Group

The group has been observed using widely-available tools such as the Remote Access Trojan (RAT) called “njRAT”...

SilverTerrier

The top 10 of the RATs used in Nigerian BEC scams is formed by NetWire, DarkComet, NanoCore, LuminosityLink, Remcos, ImminentMonitor, NJRat, Quasar, Adwind, and Hworm.

M38dHhM

This article presents a reverse engineering analysis of njRAT v0.7. njRAT, also known as Bladabindi, is a remote access tool (RAT) with user interface which allows the operator to control the victim’s computer.

Exploited software

Vulnerabilities linked to njRAT

6 CVEs

MITRE ATT&CK

njRAT in ATT&CK

102 distinct techniques

Techniques

102 techniques
T1071 Application Layer Protocol T1059.005 Visual Basic T1059.001 PowerShell T1588.001 Malware T1113 Screen Capture T1132 Data Encoding T1057 Process Discovery T1555.003 Credentials from Web Browsers T1105 Ingress Tool Transfer T1547.001 Registry Run Keys / Startup Folder T1027.004 Compile After Delivery T1112 Modify Registry T1082 System Information Discovery T1071.001 Web Protocols T1106 Native API T1083 File and Directory Discovery T1056.001 Keylogging T1555 Credentials from Password Stores T1033 System Owner/User Discovery T1005 Data from Local System T1041 Exfiltration Over C2 Channel T1547 Boot or Logon Autostart Execution T1059.003 Windows Command Shell T1620 Reflective Code Loading T1566 Phishing T1497.001 System Checks T1055 Process Injection T1566.001 Spearphishing Attachment T1204.002 Malicious File T1480.002 Mutual Exclusion T1203 Exploitation for Client Execution T1543 Create or Modify System Process T1036 Masquerading T1489 Service Stop T1218.005 Mshta T1219 Remote Access Tools T1070.004 File Deletion T1564.001 Hidden Files and Directories T1027 Obfuscated Files or Information T1123 Audio Capture T1010 Application Window Discovery T1027.007 Dynamic API Resolution T1204 User Execution T1218 System Binary Proxy Execution T1132.001 Standard Encoding T1049 System Network Connections Discovery T1095 Non-Application Layer Protocol T1518 Software Discovery T1012 Query Registry T1007 System Service Discovery T1562.004 Disable or Modify System Firewall T1529 System Shutdown/Reboot T1059.007 JavaScript T1195.001 Compromise Software Dependencies and Development Tools T1562 Impair Defenses T1497 Virtualization/Sandbox Evasion T1059 Command and Scripting Interpreter T1537 Transfer Data to Cloud Account T1589 Gather Victim Identity Information T1070 Indicator Removal T1056 Input Capture T1568 Dynamic Resolution T1125 Video Capture T1486 Data Encrypted for Impact T1189 Drive-by Compromise T1140 Deobfuscate/Decode Files or Information T1027.003 Steganography T1055.012 Process Hollowing T1574.001 DLL T1127.001 MSBuild T1027.006 HTML Smuggling T1133 External Remote Services T1583 Acquire Infrastructure T1190 Exploit Public-Facing Application T1547.009 Shortcut Modification T1584.005 Botnet T1564 Hide Artifacts T1560 Archive Collected Data T1129 Shared Modules T1091 Replication Through Removable Media T1656 Impersonation T1583.001 Domains T1102.002 Bidirectional Communication T1120 Peripheral Device Discovery T1657 Financial Theft T1566.002 Spearphishing Link T1561.002 Disk Structure Wipe T1018 Remote System Discovery T1036.005 Match Legitimate Resource Name or Location T1573.001 Symmetric Cryptography T1568.002 Domain Generation Algorithms T1102 Web Service T1571 Non-Standard Port T1518.001 Security Software Discovery T1562.001 Disable or Modify Tools T1036.004 Masquerade Task or Service T1573.002 Asymmetric Cryptography T1499 Endpoint Denial of Service T1115 Clipboard Data T1053.005 Scheduled Task T1008 Fallback Channels T1134 Access Token Manipulation

Reporting

Research mentioning njRAT

Jul 17
Levelblue Spiderlabs

Still Circling: Blind Eagle's Toolkit Keeps Evolving

Blind Eagle, also tracked as TAG-144, APT-C-36, and linked by some researchers to Red Akodon, continued targeting organizations across South America with a sustained emphasis on Colombian government entities at the local, municipal, and federal levels. Researchers described multi-stage intrusion chains using spearphishing, including compromised Colombian government email accounts, to deliver commodity and cracked remote access trojans through exposed Apache staging servers, dynamic DNS infrastructure, and legitimate internet services used for payload staging. The group has remained active since at least 2018, blending credential theft, financial crime, and surveillance-oriented collection against public-sector targets. Recent activity shows the actor refining rather than replacing its established toolkit. Investigators observed VBScript-to-PowerShell delivery chains, steganography to conceal payloads in image files, a new JavaScript stage with custom AES-based string obfuscation, an AutoIt3 RunPE loader fetched from raw.githubusercontent.com, and repeated use of the "Photo Studio" persistence disguise. The most significant upgrade was a new AsyncRAT variant, JC-46, which adds WNF-based process injection, custom Base28 encoding, HVNC support for banking fraud, browser profile cloning, and a bypass for Chrome App-Bound Encryption v20, while the group continued reusing VPN-linked command-and-control infrastructure and familiar dynamic DNS patterns.

Jan 1
Zscaler Threat Labz

Middle East users targeted by Molerats APT | Zscaler Blog

Multiple cyber-espionage operations targeted الفلسطينيين, activists, and organizations in the Palestinian territories with politically themed phishing lures and fake documents that delivered custom backdoors including Micropsia, Spark, Pierogi, and Scote. Reporting from Cisco Talos, Cybereason, and Palo Alto Networks links the activity to long-running Middle East-focused threat actors Arid Viper and MoleRATs (also known as the Gaza Cybergang), which repeatedly used Arabic-language decoys tied to regional politics, social-engineering archives hosted on services such as Dropbox and Egnyte, malicious RTF and Word files, and self-extracting executables to infect victims. The malware families provided persistent remote access and espionage capabilities including host reconnaissance, command execution, keylogging, screenshot capture, audio recording, file transfer, and HTTP-based command-and-control. Researchers said the operators also used evasion and targeting checks such as security-product discovery, Arabic language or keyboard validation, packers, and abuse of third-party platforms including Pastebin, Google+, and URL shorteners to hide infrastructure and retrieve C2 data. Across the campaigns, analysts observed largely consistent tradecraft over several years, indicating sustained intelligence collection against Palestinian political and civil-society targets despite repeated public exposure.

Aug 26
Recorded Future

TAG-144’s Persistent Grip on South American Organizations

Jan 1
Cybereason

New Cyber Espionage Campaigns Targeting Palestinians - Part 2: The Discovery of the New, Mysterious Pierogi Backdoor

Jan 1
Cybereason

New Malware Arsenal Abusing Cloud Platforms in Middle East Espionage Campaign

Nov 17
Mitre Attack

Molerats, Operation Molerats, Gaza Cybergang, Group G0021 | MITRE ATT&CK®

May 25
Cyble Blog Historic

Invicta Stealer Spreads Via Fake GoDaddy Refund Invoices

Invicta Stealer is being spread through phishing emails that impersonate GoDaddy refund invoices, using an infection chain that begins with a malicious HTML attachment and progresses through ZIP, LNK, HTA, and PowerShell stages before installing the information-stealing malware. Researchers said the malware’s developer has promoted the family on Telegram, YouTube, and GitHub, including a free builder that appears to have lowered the barrier to entry for other threat actors and increased the stealer’s circulation. Once executed by the victim, Invicta Stealer gathers extensive host and user data, including browser information, Discord data, cryptocurrency wallet contents, Steam and KeePass artifacts, installed application details, and files from Desktop and Documents, then compresses and exfiltrates the data to a Discord webhook or other command-and-control endpoint. The campaign aligns with common user execution tradecraft in phishing-led intrusions, and the malware also uses anti-analysis features such as encrypted strings, syscalls, and multithreading while collecting system and application context from infected machines.

Mar 1
Elastic Security Labs

Detect Credential Access with Elastic Security | Elastic Security Labs

Elastic Endpoint Security added kernel-driver-derived file and registry telemetry to detect access to sensitive credential stores, including browser data, Windows SAM and LSA secrets, cached domain credentials, credential files, and Windows Credential Manager. Its behavior protections can block high-confidence credential-theft activity associated with tools and malware such as Mimikatz, LaZagne, AgentTesla, FormBook, and Poulight Stealer; KQL and EQL hunting can also identify processes opening multiple sensitive stores or SMB access following a network logon. Attackers commonly extract saved browser usernames, passwords, cookies, and session tokens from stores such as Chrome’s Login Data and Firefox’s key3.db, key4.db, and logins.json. They also dump Windows LSA secrets and cached domain credentials using utilities including Mimikatz, reg save, Impacket secretsdump.py, CrackMapExec, and gsecdump. Cached Windows credentials are generally stored as DCC2/MS-Cache v2 hashes and require offline cracking rather than pass-the-hash, while Linux Active Directory integrations may retain cached credentials in SSSD or Quest database files.

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.