Skip to content

STRRAT

STRRAT, also known as Strigoi Master, is a Java-based remote access trojan targeting Windows systems.

Profile source: Mallory opens in a new tab

STRRAT

Family profile

STRRAT, also known as Strigoi Master, is a Java-based remote access trojan targeting Windows systems. Active since at least 2020, it is commonly distributed through phishing and malspam campaigns using malicious JAR attachments, macro-enabled Office documents, Java-based downloaders, and archives or installer files crafted to disguise the payload. Some campaigns bundle a Java Runtime Environment so the malware can execute even when Java is not already installed, while others rely on Java already being present. STRRAT has also been observed appended to MSI installers to hinder superficial analysis.

The malware provides broad remote administration and post-compromise functionality. It can execute shell and PowerShell commands, manage files, enumerate processes, capture the screen, and operate a reverse proxy. STRRAT supports credential theft from multiple browsers and email clients, including Chromium-based browsers, Firefox, Outlook, Thunderbird, and Foxmail, and includes both keylogging and offline log collection capabilities. It performs host reconnaissance and can attempt privilege escalation. Persistence has been observed through Startup-folder placement, scheduled tasks, and Windows Run-key autoruns.

Some variants can deploy components associated with hidden or wrapped Remote Desktop access to enable interactive remote control. STRRAT also contains a ransomware-themed module. In stronger implementations, this module encrypts user files in common profile directories and can display a ransom note; in other observed variants, it merely renames files with a dedicated extension without performing real encryption. This indicates the family has evolved over time and that capability may vary by sample.

STRRAT is frequently associated with commodity cybercrime activity rather than bespoke espionage tooling. It has been linked to phishing operations targeting business users with shipping, payment, order, and request-themed lures, and has appeared in campaigns affecting sectors such as aviation, aerospace, transportation, manufacturing, and defense through actors including TA2541. It has also been used historically by the cluster tracked as Bloody Wolf before that actor shifted toward abusing legitimate remote administration software. The malware is commonly obfuscated, including with Java obfuscators, and uses encrypted configuration data to conceal command-and-control settings and hinder analysis.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Keylogging
  • Persistence
  • Post Exploitation
  • Privilege Escalation
  • Reconnaissance

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 17, 2026
Last activity
Sep 23, 2026
Feed role
C2 / Distribution
Host form
1 IP / 6 hostnames

Leading locations

  • US3
  • ES2
  • DE1

Leading providers

  • M247 Europe SRL2
  • UnReal Servers, LLC2
  • CHANGEIP COM1
  • Leaseweb Deutschland GmbH1

Infrastructure traits

  • Hosting 6

Samples

Recent associated samples

Reported operators

Threat actors

2 named in public reporting
TA2541

In recent campaigns, vjw0rm and STRRAT also leveraged task creation and adding entries to the registry.

Bloody Wolf

Historically, the group’s weapon of choice was the remote access Trojan (RAT) STRRAT, also known as Strigoi Master.

MITRE ATT&CK

STRRAT in ATT&CK

39 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.