Skip to content

njRAT

njRAT, also known as Bladabindi and NJW0rm, is a commodity Windows remote access Trojan written for the .NET ecosystem and widely used by cybercriminal and espionage operators.

Profile source: Mallory opens in a new tab

njRAT

Family profile

njRAT, also known as Bladabindi and NJW0rm, is a commodity Windows remote access Trojan written for the .NET ecosystem and widely used by cybercriminal and espionage operators. It provides persistent unauthorized remote access and supports interactive surveillance and follow-on payload delivery. Documented capabilities include keylogging, screenshot capture, webcam access, microphone control, download-and-execute of additional malware, registry querying and modification, current-user enumeration, camera detection, removable-drive detection, and process-injection-related behavior. Analysis of staged infections has also shown socket-based data transmission and heavy use of obfuscation across intermediate loaders and scripts.

Observed delivery chains include spearphishing and phishing lures using weaponized Office documents with macros or exploit documents, as well as staged script-based loaders that retrieve additional components from paste or text-hosting services. njRAT has also appeared in broader malware distribution ecosystems involving crypters and commodity loaders, and has been distributed by actors using email campaigns and socially engineered lures. In some campaigns it has been dropped alongside or instead of other commodity RATs such as AsyncRAT, Remcos, and XWorm.

njRAT has been used by multiple threat actors and intrusion sets, including activity associated with Aquatic Panda, TA558, Gamaredon, and Transparent Tribe-related operations. It has been observed in campaigns targeting government, diplomatic, military, and regional victims, including Indian and Ukrainian targets, as well as in more general cybercriminal operations. Its longevity, low barrier to acquisition, and broad surveillance feature set have made it a recurring tool in both opportunistic and targeted intrusions.

Capabilities

  • Defense Evasion
  • Exfiltration
  • Keylogging
  • Persistence
  • Post Exploitation
  • Process Injection
  • Reconnaissance

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 1, 2026
Last activity
Aug 8, 2026
Feed role
C2 / Distribution
Host form
36 IP / 39 hostnames

Leading locations

  • CN16
  • US10
  • DE9
  • RU5
  • GB4
  • NL4
  • KR3
  • LU3
  • SA2
  • CA1
  • CY1
  • FR1

Leading providers

  • CHINA UNICOM China169 Backbone4
  • Hangzhou Alibaba Advertising Co.,Ltd.4
  • FEMO IT SOLUTIONS LIMITED3
  • Ghosty Networks LLC3
  • Shenzhen Tencent Computer Systems Company Limited3
  • Beget LLC2

Infrastructure traits

  • Hosting 47
  • Anycast 3
  • Vpn 2
  • Proxy 1

Samples

Recent associated samples

Reported operators

Threat actors

9 named in public reporting
APT-C-36

the payloads riding on top of them (NjRAT, AsyncRAT, LimeRAT) have barely changed in years

Gamaredon Group

The group has been observed using widely-available tools such as the Remote Access Trojan (RAT) called β€œnjRAT”...

APT41

Aquatic Panda has acquired and used njRAT in its operations.

Transparent Tribe

This site is likely operated by the same actor(s) that carried out the previously discussed attacks on Indian embassy officials based on shared C&C infrastructure... lure Indian military officials into becoming infected with MSIL/Crimson, njRAT, and possibly other malicious tools.

TA558

While the actor favors VenomRAT, TA558 also distributes other commodity malware including njRAT, Remcos RAT, and recently XWorm and PDQ Connect.

SilverTerrier

The top 10 of the RATs used in Nigerian BEC scams is formed by NetWire, DarkComet, NanoCore, LuminosityLink, Remcos, ImminentMonitor, NJRat, Quasar, Adwind, and Hworm.

Group5

"However, the ultimate malware payload in this case is njRat, another well-known RAT tool."

RATicate

"Some of the payloads identified for campaign 2... included... RAT Bladabindi"

M38dHhM

This article presents a reverse engineering analysis of njRAT v0.7. njRAT, also known as Bladabindi, is a remote access tool (RAT) with user interface which allows the operator to control the victim’s computer.

Exploited software

Vulnerabilities linked to njRAT

2 CVEs

MITRE ATT&CK

njRAT in ATT&CK

89 distinct techniques

Techniques

89 techniques
T1125 Video Capture T1588.001 Malware T1071.001 Web Protocols T1113 Screen Capture T1056.001 Keylogging T1219 Remote Access Tools T1102.002 Bidirectional Communication T1566 Phishing T1547.001 Registry Run Keys / Startup Folder T1012 Query Registry T1082 System Information Discovery T1120 Peripheral Device Discovery T1112 Modify Registry T1123 Audio Capture T1059.001 PowerShell T1059.005 Visual Basic T1027 Obfuscated Files or Information T1105 Ingress Tool Transfer T1071 Application Layer Protocol T1204.002 Malicious File T1055 Process Injection T1083 File and Directory Discovery T1033 System Owner/User Discovery T1036 Masquerading T1203 Exploitation for Client Execution T1189 Drive-by Compromise T1204 User Execution T1566.001 Spearphishing Attachment T1132 Data Encoding T1057 Process Discovery T1005 Data from Local System T1497.001 System Checks T1059.003 Windows Command Shell T1041 Exfiltration Over C2 Channel T1070.004 File Deletion T1555.003 Credentials from Web Browsers T1657 Financial Theft T1566.002 Spearphishing Link T1027.006 HTML Smuggling T1561.002 Disk Structure Wipe T1018 Remote System Discovery T1027.003 Steganography T1036.005 Match Legitimate Resource Name or Location T1573.001 Symmetric Cryptography T1568.002 Domain Generation Algorithms T1102 Web Service T1055.012 Process Hollowing T1571 Non-Standard Port T1518.001 Security Software Discovery T1562.001 Disable or Modify Tools T1529 System Shutdown/Reboot T1562.004 Disable or Modify System Firewall T1091 Replication Through Removable Media T1036.004 Masquerade Task or Service T1573.002 Asymmetric Cryptography T1140 Deobfuscate/Decode Files or Information T1095 Non-Application Layer Protocol T1564.001 Hidden Files and Directories T1562 Impair Defenses T1499 Endpoint Denial of Service T1115 Clipboard Data T1053.005 Scheduled Task T1008 Fallback Channels T1620 Reflective Code Loading T1059 Command and Scripting Interpreter T1129 Shared Modules T1134 Access Token Manipulation T1106 Native API T1489 Service Stop T1560 Archive Collected Data T1070.007 Clear Network Connection History and Configurations T1568.001 Fast Flux DNS T1056 Input Capture T1132.001 Standard Encoding T1092 Communication Through Removable Media T1021.001 Remote Desktop Protocol T1027.004 Compile After Delivery T1027.013 Encrypted/Encoded File T1010 Application Window Discovery T1027.002 Software Packing T1218.010 Regsvr32 T1497.003 Time Based Checks T1069.001 Local Groups T1608.004 Drive-by Target T1127.001 MSBuild T1490 Inhibit System Recovery T1027.011 Fileless Storage T1622 Debugger Evasion T1070.009 Clear Persistence

Reporting

Research mentioning njRAT

Jul 17
Levelblue Spiderlabs

Still Circling: Blind Eagle's Toolkit Keeps Evolving

Blind Eagle, also tracked as TAG-144, APT-C-36, and linked by some researchers to Red Akodon, continued targeting organizations across South America with a sustained emphasis on Colombian government entities at the local, municipal, and federal levels. Researchers described multi-stage intrusion chains using spearphishing, including compromised Colombian government email accounts, to deliver commodity and cracked remote access trojans through exposed Apache staging servers, dynamic DNS infrastructure, and legitimate internet services used for payload staging. The group has remained active since at least 2018, blending credential theft, financial crime, and surveillance-oriented collection against public-sector targets. Recent activity shows the actor refining rather than replacing its established toolkit. Investigators observed VBScript-to-PowerShell delivery chains, steganography to conceal payloads in image files, a new JavaScript stage with custom AES-based string obfuscation, an AutoIt3 RunPE loader fetched from raw.githubusercontent.com, and repeated use of the "Photo Studio" persistence disguise. The most significant upgrade was a new AsyncRAT variant, JC-46, which adds WNF-based process injection, custom Base28 encoding, HVNC support for banking fraud, browser profile cloning, and a bypass for Chrome App-Bound Encryption v20, while the group continued reusing VPN-linked command-and-control infrastructure and familiar dynamic DNS patterns.

Aug 26
Recorded Future

TAG-144’s Persistent Grip on South American Organizations

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.