Skip to content

Lilith

Lilith is a malware name used for at least two distinct Windows threats in public reporting: an open-source remote administration tool and a separate ransomware family.

Profile source: Mallory opens in a new tab

Lilith

Family profile

Lilith is a malware name used for at least two distinct Windows threats in public reporting: an open-source remote administration tool and a separate ransomware family. The remote administration tool variant is a lightweight console-based C++ RAT for Windows that supports remote command execution through command shells and PowerShell, multiple client management, broadcast tasking, keylogging, startup persistence, and self-removal. Its modular design also allows operators to extend functionality with additional utilities and scripts. These capabilities make it suitable for unauthorized remote access and post-compromise control. Lilith has also been observed as a commodity RAT used by the SideCopy threat actor alongside other remote access tools in campaigns targeting government-related entities in India and Pakistan.

Separately, Lilith ransomware is a Windows 64-bit C/C++ console executable used for file encryption and extortion. It enumerates drives and files, excludes certain system-critical file types from encryption, terminates selected processes, interacts with the Windows Service Control Manager to stop services, encrypts victim files using Windows cryptographic APIs, renames encrypted files with a dedicated extension, and drops ransom notes threatening data leakage if payment negotiations do not begin within a short deadline. This behavior is consistent with modern double-extortion ransomware operations.

Because the same name is applied to materially different malware families, Lilith is an ambiguous designation rather than a single well-defined malware family.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Extortion
  • Keylogging
  • Persistence
  • Post Exploitation

Operational record

1
YARA rules
1
Ransom notes
1
Leak sites
0 available

MITRE ATT&CK

Lilith in ATT&CK

8 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.