In recent campaigns, vjw0rm and STRRAT also leveraged task creation and adding entries to the registry.
STRRAT
STRRAT is a Java-based remote access trojan (RAT), also known as Strigoi Master, with observed versioning including "STRRAT 1.2." It is Windows-focused despite being Java-based.
Profile source: Mallory opens in a new tabSTRRAT
Family profile
STRRAT is a Java-based remote access trojan (RAT), also known as Strigoi Master, with observed versioning including "STRRAT 1.2." It is Windows-focused despite being Java-based. Reported delivery includes spam and phishing campaigns using malicious JAR attachments, as well as malicious Java-based downloaders. Public reporting also states STRRAT has been hosted or delivered via public services including AWS and GitHub, and has appeared in malspam campaigns using business-themed lures such as "Offers" and "Requests."
Documented behavior includes extraction and execution of VBScript stages via wscript.exe, use of PowerShell to decode and run additional content, writing the final payload as %APPDATA%\ntfsmgr.jar, and persistence via a Windows Run key named ntfsmgr. Other reporting associates STRRAT campaigns with scheduled task creation and registry-based persistence. The malware is obfuscated with Allatori, uses AES-encrypted strings and configuration, and downloads dependencies from a hardcoded URL including hxxp://jbfrost.live/strigoi/lib.zip. Configuration has been described as AES-encrypted with the password "strgoi."
Capabilities directly described in the source material include credential theft from Firefox, Internet Explorer, Chrome, Foxmail, Outlook, and Thunderbird; keylogging with both immediate exfiltration and offline modes; remote command execution; PowerShell execution; file management; process listing; remote screen control; and reverse proxying. STRRAT can also download and install RDPWrap / Hidden RDP components to enable or abuse Remote Desktop on Windows, including retrieval of a component from hxxp://wshsoft.company/multrdp(.)jpg and use of an HRDPInst.exe installer. A ransomware-related module is present with commands rw-encrypt, rw-decrypt, and show-msg, but the described "encryption" only renames files by appending the .crimson extension rather than performing real cryptographic encryption.
STRRAT has been associated with multiple threat actors and campaigns in the provided content. Proofpoint links it to TA2541, a persistent cybercriminal actor targeting aviation, aerospace, transportation, manufacturing, and defense organizations since at least 2017, using phishing lures and cloud-hosted payload chains. STRRAT is also described as the historical malware of choice for Bloody Wolf / Stan Ghouls, which targeted entities in Kazakhstan, Russia, Kyrgyzstan, and Uzbekistan, including government, finance, manufacturing, and IT-related victims, before later shifting to NetSupport. Additional reporting notes infection attempts against German customers.
High-confidence indicators and artifacts mentioned in the content include the attachment name NEW ORDER.jar; dropped files bqhoonmpho.vbs, %APPDATA%\edeKbMYRtr.vbs, and %APPDATA%\ntfsmgr.jar; package name strpayload; dependency system-hook-3.5.jar; the Run key name ntfsmgr; the URL hxxp://jbfrost.live/strigoi/lib.zip; and the RDP-related URL hxxp://wshsoft.company/multrdp(.)jpg.
Reported operators
Threat actors
2 named in public reportingHistorically, the group’s weapon of choice was the remote access Trojan (RAT) STRRAT, also known as Strigoi Master.
MITRE ATT&CK
STRRAT in ATT&CK
25 distinct techniquesTechniques
25 techniquesReporting
Research mentioning STRRAT
Bloody Wolf Hackers Attacking Organizations to Deploy NetSupport RAT and Gain Remote Access
"While they previously favored the STRRAT remote access trojan..."
Bloody Wolf Targets Uzbekistan, Russia Using NetSupport RAT in Spear-Phishing Campaign
...a departure for the threat actor, which previously leveraged STRRAT (aka Strigoi Master) in its attacks.
Stan Ghouls attacks in Russia and Uzbekistan: NetSupport RAT and potential IoT interest | Securelist
Historically, the group’s weapon of choice was the remote access Trojan (RAT) STRRAT, also known as Strigoi Master.
News - Malware & Hoax - TG Soft Cyber Security Specialist
10/02 /2026 ... STRRAT - spread through a campaign themed " Offers" .
Bloody Wolf Expands Java-based NetSupport RAT Attacks in Kyrgyzstan and Uzbekistan
Bloody Wolf is the name assigned to a hacking group of unknown provenance that has used spear-phishing attacks to target entities in Kazakhstan and Russia using tools like STRRAT and NetSupport.
2025W26 Weekly report => 23/06 2K25 - 29/06 2K25 MalSpam campaigns targeting Italy
26/06/2025 STRRAT - spread through a campaign themed "Requests".
2025W25 Weekly report => 16/06 2K25 - 22/06 2K25 MalSpam campaigns targeting Italy
The week was characterized by Password Stealer of the Families: FormBook, Remcos, STRRAT and VIPKeylogger. 19/06/2025 STRRAT - spread through a campaign themed "Requests".
安全事件周报 2024-03-11 第11周
新的网络钓鱼活动通过基于 Java 的恶意下载程序传播 VCURMS 和 STRRAT 等远程访问木马 (RAT)。攻击者将恶意软件存储在 Amazon Web Services (AWS) 和 GitHub 等公共服务上,并使用商业保护程序来避免检测到恶意软件。