Skip to content

RunningRAT

RunningRAT is a remote access trojan malware family.

Profile source: Mallory opens in a new tab

RunningRAT

Family profile

RunningRAT is a remote access trojan malware family. The provided content attributes to it multiple post-compromise collection, staging, defense-evasion, and cleanup capabilities on Windows systems. Specifically, RunningRAT contains code to open and copy data from the clipboard, capture keystrokes and send them back to its C2 server, compress files, delete files from the victim machine, clear Windows event logs, and kill running antimalware processes. The content also notes that RunningRAT uses a batch file to kill a security program task and then attempts to remove itself. Version references in the content indicate evolution from v1.1 to v1.2. Separately, Hunt.IO reportedly assessed related malware as a variant of RunningRAT in public reporting, but the content does not provide high-confidence attribution of RunningRAT to a specific threat actor, industry targeting, or infection vector.

MITRE ATT&CK

RunningRAT in ATT&CK

13 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.