RunningRAT
RunningRAT is a Windows remote access trojan associated with post-compromise surveillance, collection, and anti-forensic activity.
Profile source: Mallory opens in a new tabRunningRAT
Family profile
RunningRAT is a Windows remote access trojan associated with post-compromise surveillance, collection, and anti-forensic activity. Reported capabilities include keystroke logging with transmission of captured input to command-and-control infrastructure, clipboard collection, file compression for staging or exfiltration, deletion of files from the victim system, termination of antimalware processes, and clearing of Windows event logs. Some variants also use batch-script logic to terminate security software tasks and attempt self-removal, indicating an emphasis on defense evasion and operational cleanup. Public reporting has also described malware variants overlapping with RunningRAT in intrusions involving deployment after initial server compromise, where the malware was used to establish persistent remote control on Windows hosts. The family is best characterized as a RAT with collection and anti-detection features suited to espionage-oriented or hands-on-keyboard follow-on activity.
Capabilities
- Credential Theft
- Defense Evasion
- Exfiltration
- Keylogging
MITRE ATT&CK
RunningRAT in ATT&CK
13 distinct techniquesReporting
Research mentioning RunningRAT
Virus Bulletin :: Collector-stealer: a Russian origin credential and information extractor
Collector Stealer—also marketed as COLLECTOR Project, CollectorGoomba, and formerly Memory Project—was sold as a Russian-language spyware service and used to steal saved browser credentials, cookies, personal data, screenshots, Telegram and Steam data, and cryptocurrency wallet information from infected Windows systems. Researchers said the malware was spread through phishing portals, fake software downloads, and bundled crack or riskware tools such as KMSAuto, often disguised as miners, game utilities, or activation packages. On infected hosts, it gathered data from browsers and applications, captured screenshots, scanned directories, extracted SQLite-stored information, and staged the loot in ZIP or RAR archives before sending it to attacker-controlled panels over HTTP POST. Analysis of the malware’s infrastructure showed that some builds fetched their command-and-control destination from a text file hosted on GitHub, with a fallback to a hard-coded justns.ru subdomain if retrieval failed. After the malicious GitHub repository was reported and removed, affected samples attempted to exfiltrate to an invalid 404: Not Found.ru destination and crashed, temporarily disrupting those variants. Operators later updated newer samples to use upaste[.]me for C2 redirection instead, indicating the stealer remained under active development and continued to evolve its exfiltration workflow and delivery ecosystem.