Last seven days
- First activity
- Aug 6, 2026
- Last activity
- Aug 6, 2026
- Feed role
- C2 / Distribution
- Host form
- 0 IP / 2 hostnames
STRRAT is a Java-based remote access trojan (RAT), also known as Strigoi Master, with observed versioning including "STRRAT 1.2." It is Windows-focused despite being Java-based.
Profile source: Mallory opens in a new tabSTRRAT
STRRAT is a Java-based remote access trojan (RAT), also known as Strigoi Master, with observed versioning including "STRRAT 1.2." It is Windows-focused despite being Java-based. Reported delivery includes spam and phishing campaigns using malicious JAR attachments, as well as malicious Java-based downloaders. Public reporting also states STRRAT has been hosted or delivered via public services including AWS and GitHub, and has appeared in malspam campaigns using business-themed lures such as "Offers" and "Requests."
Documented behavior includes extraction and execution of VBScript stages via wscript.exe, use of PowerShell to decode and run additional content, writing the final payload as %APPDATA%\ntfsmgr.jar, and persistence via a Windows Run key named ntfsmgr. Other reporting associates STRRAT campaigns with scheduled task creation and registry-based persistence. The malware is obfuscated with Allatori, uses AES-encrypted strings and configuration, and downloads dependencies from a hardcoded URL including hxxp://jbfrost.live/strigoi/lib.zip. Configuration has been described as AES-encrypted with the password "strgoi."
Capabilities directly described in the source material include credential theft from Firefox, Internet Explorer, Chrome, Foxmail, Outlook, and Thunderbird; keylogging with both immediate exfiltration and offline modes; remote command execution; PowerShell execution; file management; process listing; remote screen control; and reverse proxying. STRRAT can also download and install RDPWrap / Hidden RDP components to enable or abuse Remote Desktop on Windows, including retrieval of a component from hxxp://wshsoft.company/multrdp(.)jpg and use of an HRDPInst.exe installer. A ransomware-related module is present with commands rw-encrypt, rw-decrypt, and show-msg, but the described "encryption" only renames files by appending the .crimson extension rather than performing real cryptographic encryption.
STRRAT has been associated with multiple threat actors and campaigns in the provided content. Proofpoint links it to TA2541, a persistent cybercriminal actor targeting aviation, aerospace, transportation, manufacturing, and defense organizations since at least 2017, using phishing lures and cloud-hosted payload chains. STRRAT is also described as the historical malware of choice for Bloody Wolf / Stan Ghouls, which targeted entities in Kazakhstan, Russia, Kyrgyzstan, and Uzbekistan, including government, finance, manufacturing, and IT-related victims, before later shifting to NetSupport. Additional reporting notes infection attempts against German customers.
High-confidence indicators and artifacts mentioned in the content include the attachment name NEW ORDER.jar; dropped files bqhoonmpho.vbs, %APPDATA%\edeKbMYRtr.vbs, and %APPDATA%\ntfsmgr.jar; package name strpayload; dependency system-hook-3.5.jar; the Run key name ntfsmgr; the URL hxxp://jbfrost.live/strigoi/lib.zip; and the RDP-related URL hxxp://wshsoft.company/multrdp(.)jpg.
C2 tracking
Derp observations, rolling seven-day window
Samples
1162b0a85a471b942f594b6707c79652b49d0d349e4aca2e0779c42577291ec3 66ca166c4e0a6d1223c1bd93f2ca1556dfdf9be208e8d14ddc1bf7fec1adaeb8 cc75bd30c623f080ee5dd003c2802a9c97a008f9fd6f4a1c4113a27b1242d290 cd95bd16eda71385f1c372910e0da074062ae7db5f9c3de90980f49e3e955f2e Reported operators
In recent campaigns, vjw0rm and STRRAT also leveraged task creation and adding entries to the registry.
Historically, the group’s weapon of choice was the remote access Trojan (RAT) STRRAT, also known as Strigoi Master.
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.