Skip to content
Malware family

STRRAT

STRRAT is a Java-based remote access trojan (RAT), also known as Strigoi Master, with observed versioning including "STRRAT 1.2." It is Windows-focused despite being Java-based.

Profile source: Mallory opens in a new tab

STRRAT

Family profile

STRRAT is a Java-based remote access trojan (RAT), also known as Strigoi Master, with observed versioning including "STRRAT 1.2." It is Windows-focused despite being Java-based. Reported delivery includes spam and phishing campaigns using malicious JAR attachments, as well as malicious Java-based downloaders. Public reporting also states STRRAT has been hosted or delivered via public services including AWS and GitHub, and has appeared in malspam campaigns using business-themed lures such as "Offers" and "Requests."

Documented behavior includes extraction and execution of VBScript stages via wscript.exe, use of PowerShell to decode and run additional content, writing the final payload as %APPDATA%\ntfsmgr.jar, and persistence via a Windows Run key named ntfsmgr. Other reporting associates STRRAT campaigns with scheduled task creation and registry-based persistence. The malware is obfuscated with Allatori, uses AES-encrypted strings and configuration, and downloads dependencies from a hardcoded URL including hxxp://jbfrost.live/strigoi/lib.zip. Configuration has been described as AES-encrypted with the password "strgoi."

Capabilities directly described in the source material include credential theft from Firefox, Internet Explorer, Chrome, Foxmail, Outlook, and Thunderbird; keylogging with both immediate exfiltration and offline modes; remote command execution; PowerShell execution; file management; process listing; remote screen control; and reverse proxying. STRRAT can also download and install RDPWrap / Hidden RDP components to enable or abuse Remote Desktop on Windows, including retrieval of a component from hxxp://wshsoft.company/multrdp(.)jpg and use of an HRDPInst.exe installer. A ransomware-related module is present with commands rw-encrypt, rw-decrypt, and show-msg, but the described "encryption" only renames files by appending the .crimson extension rather than performing real cryptographic encryption.

STRRAT has been associated with multiple threat actors and campaigns in the provided content. Proofpoint links it to TA2541, a persistent cybercriminal actor targeting aviation, aerospace, transportation, manufacturing, and defense organizations since at least 2017, using phishing lures and cloud-hosted payload chains. STRRAT is also described as the historical malware of choice for Bloody Wolf / Stan Ghouls, which targeted entities in Kazakhstan, Russia, Kyrgyzstan, and Uzbekistan, including government, finance, manufacturing, and IT-related victims, before later shifting to NetSupport. Additional reporting notes infection attempts against German customers.

High-confidence indicators and artifacts mentioned in the content include the attachment name NEW ORDER.jar; dropped files bqhoonmpho.vbs, %APPDATA%\edeKbMYRtr.vbs, and %APPDATA%\ntfsmgr.jar; package name strpayload; dependency system-hook-3.5.jar; the Run key name ntfsmgr; the URL hxxp://jbfrost.live/strigoi/lib.zip; and the RDP-related URL hxxp://wshsoft.company/multrdp(.)jpg.

Reported operators

Threat actors

2 named in public reporting
TA2541

In recent campaigns, vjw0rm and STRRAT also leveraged task creation and adding entries to the registry.

Bloody Wolf

Historically, the group’s weapon of choice was the remote access Trojan (RAT) STRRAT, also known as Strigoi Master.

MITRE ATT&CK

STRRAT in ATT&CK

25 distinct techniques

Reporting

Research mentioning STRRAT

Feb 10
Cyber Security News

Bloody Wolf Hackers Attacking Organizations to Deploy NetSupport RAT and Gain Remote Access

"While they previously favored the STRRAT remote access trojan..."

Feb 9
The Hacker News

Bloody Wolf Targets Uzbekistan, Russia Using NetSupport RAT in Spear-Phishing Campaign

...a departure for the threat actor, which previously leveraged STRRAT (aka Strigoi Master) in its attacks.

Feb 5
Securelist

Stan Ghouls attacks in Russia and Uzbekistan: NetSupport RAT and potential IoT interest | Securelist

Historically, the group’s weapon of choice was the remote access Trojan (RAT) STRRAT, also known as Strigoi Master.

Jan 12
Virit

News - Malware & Hoax - TG Soft Cyber Security Specialist

10/02 /2026 ... STRRAT - spread through a campaign themed " Offers" .

Nov 27
The Hacker News

Bloody Wolf Expands Java-based NetSupport RAT Attacks in Kyrgyzstan and Uzbekistan

Bloody Wolf is the name assigned to a hacking group of unknown provenance that has used spear-phishing attacks to target entities in Kazakhstan and Russia using tools like STRRAT and NetSupport.

Jun 23
Virit

2025W26 Weekly report => 23/06 2K25 - 29/06 2K25 MalSpam campaigns targeting Italy

26/06/2025 STRRAT - spread through a campaign themed "Requests".

Jun 16
Virit

2025W25 Weekly report => 16/06 2K25 - 22/06 2K25 MalSpam campaigns targeting Italy

The week was characterized by Password Stealer of the Families: FormBook, Remcos, STRRAT and VIPKeylogger. 19/06/2025 STRRAT - spread through a campaign themed "Requests".

Mar 18
Cert 360 Cn

安全事件周报 2024-03-11 第11周

新的网络钓鱼活动通过基于 Java 的恶意下载程序传播 VCURMS 和 STRRAT 等远程访问木马 (RAT)。攻击者将恶意软件存储在 Amazon Web Services (AWS) 和 GitHub 等公共服务上,并使用商业保护程序来避免检测到恶意软件。

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.