Skip to content

RunningRAT

RunningRAT is a Windows remote access trojan associated with post-compromise surveillance, collection, and anti-forensic activity.

Profile source: Mallory opens in a new tab

RunningRAT

Family profile

RunningRAT is a Windows remote access trojan associated with post-compromise surveillance, collection, and anti-forensic activity. Reported capabilities include keystroke logging with transmission of captured input to command-and-control infrastructure, clipboard collection, file compression for staging or exfiltration, deletion of files from the victim system, termination of antimalware processes, and clearing of Windows event logs. Some variants also use batch-script logic to terminate security software tasks and attempt self-removal, indicating an emphasis on defense evasion and operational cleanup. Public reporting has also described malware variants overlapping with RunningRAT in intrusions involving deployment after initial server compromise, where the malware was used to establish persistent remote control on Windows hosts. The family is best characterized as a RAT with collection and anti-detection features suited to espionage-oriented or hands-on-keyboard follow-on activity.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Keylogging

MITRE ATT&CK

RunningRAT in ATT&CK

13 distinct techniques

Reporting

Research mentioning RunningRAT

Dec 1
Virusbulletin

Virus Bulletin :: Collector-stealer: a Russian origin credential and information extractor

Collector Stealer—also marketed as COLLECTOR Project, CollectorGoomba, and formerly Memory Project—was sold as a Russian-language spyware service and used to steal saved browser credentials, cookies, personal data, screenshots, Telegram and Steam data, and cryptocurrency wallet information from infected Windows systems. Researchers said the malware was spread through phishing portals, fake software downloads, and bundled crack or riskware tools such as KMSAuto, often disguised as miners, game utilities, or activation packages. On infected hosts, it gathered data from browsers and applications, captured screenshots, scanned directories, extracted SQLite-stored information, and staged the loot in ZIP or RAR archives before sending it to attacker-controlled panels over HTTP POST. Analysis of the malware’s infrastructure showed that some builds fetched their command-and-control destination from a text file hosted on GitHub, with a fallback to a hard-coded justns.ru subdomain if retrieval failed. After the malicious GitHub repository was reported and removed, affected samples attempted to exfiltrate to an invalid 404: Not Found.ru destination and crashed, temporarily disrupting those variants. Operators later updated newer samples to use upaste[.]me for C2 redirection instead, indicating the stealer remained under active development and continued to evolve its exfiltration workflow and delivery ecosystem.

Jul 1
Vmray

Cutting-off the Command-and-Control Infrastructure of CollectorGoomba | Threat Bulletin | VMRay

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.