Skip to content

STRRAT

STRRAT is a Java-based remote access trojan (RAT), also known as Strigoi Master, with observed versioning including "STRRAT 1.2." It is Windows-focused despite being Java-based.

Profile source: Mallory opens in a new tab

STRRAT

Family profile

STRRAT is a Java-based remote access trojan (RAT), also known as Strigoi Master, with observed versioning including "STRRAT 1.2." It is Windows-focused despite being Java-based. Reported delivery includes spam and phishing campaigns using malicious JAR attachments, as well as malicious Java-based downloaders. Public reporting also states STRRAT has been hosted or delivered via public services including AWS and GitHub, and has appeared in malspam campaigns using business-themed lures such as "Offers" and "Requests."

Documented behavior includes extraction and execution of VBScript stages via wscript.exe, use of PowerShell to decode and run additional content, writing the final payload as %APPDATA%\ntfsmgr.jar, and persistence via a Windows Run key named ntfsmgr. Other reporting associates STRRAT campaigns with scheduled task creation and registry-based persistence. The malware is obfuscated with Allatori, uses AES-encrypted strings and configuration, and downloads dependencies from a hardcoded URL including hxxp://jbfrost.live/strigoi/lib.zip. Configuration has been described as AES-encrypted with the password "strgoi."

Capabilities directly described in the source material include credential theft from Firefox, Internet Explorer, Chrome, Foxmail, Outlook, and Thunderbird; keylogging with both immediate exfiltration and offline modes; remote command execution; PowerShell execution; file management; process listing; remote screen control; and reverse proxying. STRRAT can also download and install RDPWrap / Hidden RDP components to enable or abuse Remote Desktop on Windows, including retrieval of a component from hxxp://wshsoft.company/multrdp(.)jpg and use of an HRDPInst.exe installer. A ransomware-related module is present with commands rw-encrypt, rw-decrypt, and show-msg, but the described "encryption" only renames files by appending the .crimson extension rather than performing real cryptographic encryption.

STRRAT has been associated with multiple threat actors and campaigns in the provided content. Proofpoint links it to TA2541, a persistent cybercriminal actor targeting aviation, aerospace, transportation, manufacturing, and defense organizations since at least 2017, using phishing lures and cloud-hosted payload chains. STRRAT is also described as the historical malware of choice for Bloody Wolf / Stan Ghouls, which targeted entities in Kazakhstan, Russia, Kyrgyzstan, and Uzbekistan, including government, finance, manufacturing, and IT-related victims, before later shifting to NetSupport. Additional reporting notes infection attempts against German customers.

High-confidence indicators and artifacts mentioned in the content include the attachment name NEW ORDER.jar; dropped files bqhoonmpho.vbs, %APPDATA%\edeKbMYRtr.vbs, and %APPDATA%\ntfsmgr.jar; package name strpayload; dependency system-hook-3.5.jar; the Run key name ntfsmgr; the URL hxxp://jbfrost.live/strigoi/lib.zip; and the RDP-related URL hxxp://wshsoft.company/multrdp(.)jpg.

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 6, 2026
Last activity
Aug 6, 2026
Feed role
C2 / Distribution
Host form
0 IP / 2 hostnames

Leading locations

  • DE1
  • US1

Leading providers

  • Leaseweb Deutschland GmbH1
  • UnReal Servers, LLC1

Infrastructure traits

  • Hosting 2

Samples

Recent associated samples

Reported operators

Threat actors

2 named in public reporting
TA2541

In recent campaigns, vjw0rm and STRRAT also leveraged task creation and adding entries to the registry.

Bloody Wolf

Historically, the group’s weapon of choice was the remote access Trojan (RAT) STRRAT, also known as Strigoi Master.

MITRE ATT&CK

STRRAT in ATT&CK

25 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.