Last seven days
- First activity
- Sep 17, 2026
- Last activity
- Sep 23, 2026
- Feed role
- C2 / Distribution
- Host form
- 1 IP / 6 hostnames
STRRAT, also known as Strigoi Master, is a Java-based remote access trojan targeting Windows systems.
Profile source: Mallory opens in a new tabSTRRAT
STRRAT, also known as Strigoi Master, is a Java-based remote access trojan targeting Windows systems. Active since at least 2020, it is commonly distributed through phishing and malspam campaigns using malicious JAR attachments, macro-enabled Office documents, Java-based downloaders, and archives or installer files crafted to disguise the payload. Some campaigns bundle a Java Runtime Environment so the malware can execute even when Java is not already installed, while others rely on Java already being present. STRRAT has also been observed appended to MSI installers to hinder superficial analysis.
The malware provides broad remote administration and post-compromise functionality. It can execute shell and PowerShell commands, manage files, enumerate processes, capture the screen, and operate a reverse proxy. STRRAT supports credential theft from multiple browsers and email clients, including Chromium-based browsers, Firefox, Outlook, Thunderbird, and Foxmail, and includes both keylogging and offline log collection capabilities. It performs host reconnaissance and can attempt privilege escalation. Persistence has been observed through Startup-folder placement, scheduled tasks, and Windows Run-key autoruns.
Some variants can deploy components associated with hidden or wrapped Remote Desktop access to enable interactive remote control. STRRAT also contains a ransomware-themed module. In stronger implementations, this module encrypts user files in common profile directories and can display a ransom note; in other observed variants, it merely renames files with a dedicated extension without performing real encryption. This indicates the family has evolved over time and that capability may vary by sample.
STRRAT is frequently associated with commodity cybercrime activity rather than bespoke espionage tooling. It has been linked to phishing operations targeting business users with shipping, payment, order, and request-themed lures, and has appeared in campaigns affecting sectors such as aviation, aerospace, transportation, manufacturing, and defense through actors including TA2541. It has also been used historically by the cluster tracked as Bloody Wolf before that actor shifted toward abusing legitimate remote administration software. The malware is commonly obfuscated, including with Java obfuscators, and uses encrypted configuration data to conceal command-and-control settings and hinder analysis.
C2 tracking
Derp observations, rolling seven-day window
Samples
1c40688fb64c0a7cb58be42c58bfcbb6cfc93d51da6d561bb75a32de19bf25dc 1d344857c09417512d0afe65f81f9de51b41f2033dd8137dc9cdb2d2a39ee6fe 343d0f4a95e588f4b3e1888cd65f17f15591cc2a010c40baa01b2cbe68350bdb 3c842f85255896b35ec75d2aaf2629adf0315673cc746a6cda1c80516838bcad 95701b2178c9f1544146bab431311db2acc30b59e3c387e830a93a995a7764f8 1ac0a65dc2a40136f522d303037c4f7343a938ec390bc8849f0ba3b1b57ae3e8 28d598f922d5dfaf4053c59af1ebd46f21133c33d58121ef95590bf80fe9ef22 89d1d22e34e349f074065cfe4cd31b58d155833ec1746120230b4ee7ebe9f03e 9049c2435e438b14915d0dfa6af96f754d699d1d9417a10d402e31b40e6ce28c a05e19a327fb6c9208abf7866ef09c5efffabc04a80456b49c81c790a40880c5 Reported operators
In recent campaigns, vjw0rm and STRRAT also leveraged task creation and adding entries to the registry.
Historically, the group’s weapon of choice was the remote access Trojan (RAT) STRRAT, also known as Strigoi Master.
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.