Lilith
Lilith is a malware name used for at least two distinct Windows threats in public reporting: an open-source remote administration tool and a separate ransomware family.
Profile source: Mallory opens in a new tabLilith
Family profile
Lilith is a malware name used for at least two distinct Windows threats in public reporting: an open-source remote administration tool and a separate ransomware family. The remote administration tool variant is a lightweight console-based C++ RAT for Windows that supports remote command execution through command shells and PowerShell, multiple client management, broadcast tasking, keylogging, startup persistence, and self-removal. Its modular design also allows operators to extend functionality with additional utilities and scripts. These capabilities make it suitable for unauthorized remote access and post-compromise control. Lilith has also been observed as a commodity RAT used by the SideCopy threat actor alongside other remote access tools in campaigns targeting government-related entities in India and Pakistan.
Separately, Lilith ransomware is a Windows 64-bit C/C++ console executable used for file encryption and extortion. It enumerates drives and files, excludes certain system-critical file types from encryption, terminates selected processes, interacts with the Windows Service Control Manager to stop services, encrypts victim files using Windows cryptographic APIs, renames encrypted files with a dedicated extension, and drops ransom notes threatening data leakage if payment negotiations do not begin within a short deadline. This behavior is consistent with modern double-extortion ransomware operations.
Because the same name is applied to materially different malware families, Lilith is an ambiguous designation rather than a single well-defined malware family.
Capabilities
- Credential Theft
- Defense Evasion
- Exfiltration
- Extortion
- Keylogging
- Persistence
- Post Exploitation
Operational record
MITRE ATT&CK