Last seven days
- First activity
- Sep 22, 2026
- Last activity
- Sep 27, 2026
- Feed role
- C2 / Distribution
- Host form
- 4 IP / 83 hostnames
Warzone RAT, also known as Ave Maria, is a Windows remote-access trojan offered through a malware-as-a-service model and also deployed as a staged payload in targeted intrusion chains.
Profile source: Mallory opens in a new tabWarzoneRAT
Warzone RAT, also known as Ave Maria, is a Windows remote-access trojan offered through a malware-as-a-service model and also deployed as a staged payload in targeted intrusion chains. It supports remote command execution, reverse-shell access, hidden VNC-based remote desktop control, webcam capture, keylogging, browser and email-client credential theft, file operations, and process enumeration and termination. Observed variants and delivery chains have used PowerShell, process injection and process hollowing, masquerading, hidden execution, scheduled-task or startup persistence, and Windows UAC-bypass techniques. Warzone RAT has been delivered through phishing and spear-phishing campaigns using malicious Office documents, archives, macros, JavaScript, and PowerShell loaders; COVID-19-themed spam exploiting CVE-2017-11882 has also distributed it. APT-C-36 has used Warzone RAT among other commodity RATs. Campaigns targeting Indian government employees and military personnel have delivered Warzone RAT using Indian government-themed lures and were assessed to resemble Transparent Tribe and SideCopy activity.
C2 tracking
Derp observations, rolling seven-day window
Samples
1b723594e574c00aac2c946ff738a0454f7c24f6ebc84ae45a6af9628b08cb96 40b643468356c0fd751893647ad0dc9e2a0019427e4f5f0e2f6e559efcecb977 9838584fba1ebdf51d3fcd9cb0d5461d92001e574adafc826dc3ce914f7304b8 a4a0dceae8a383fc471efdc3cb0f043fd6e31ae842fd8951757cc9c3e601c634 e9554b920a4a65df1dd5809afcf5e9d0c5cd448528a03c7a232f83abcc565cd5 2fcad226b17131da4274e1b9f8f31359bdd325c9568665f08fd1f6c5d06a23ce 30955adfb864533f1d6a46b25f02aa79c5c5891d0b536eb9da9d33bcaa1061db 75f1acc1a43b319031abd03d6d6d14241e0574c50e6bc6e553201348cf8d3873 d8c3b7036cc3a1e8bdc461cc15e28f1e3cde3fba4a62fc983f4e9ada65588f31 eafdec109b69198bcb1e4ac2299a13cb409424e566491df59f7981fdcd9d87ee Reported operators
“In the past, we have observed that APT-C-36 makes use of RATs such as: ... Warzone RAT ...”
Cisco Talos recently discovered a malicious campaign targeting government employees and military personnel in the Indian sub-continent with two commercial and commodity RAT families known as NetwireRAT (aka NetwireRC) and WarzoneRAT (aka Ave Maria).
In some cases, the final stage PowerShell script contained up to seven various RATs. These are typically NjRat, BitRat, Nanocore RAT, QuasarRat, LimeRat, and Warzone.
To give an overview, here is a list of all observed tools and malware types the actor has been using in recent years: Warzone RAT / AveMaria RAT
Apart from the above legitimate tools used for malicious purposes, Scattered Spider also conducts phishing attacks to install malware like the WarZone RAT, Raccoon Stealer, and Vidar Stealer, to steal from compromised systems login credentials, cookies, and other data useful in the attack.
For remote access, YoroTrooper has also deployed commodity malware, such as AveMaria/Warzone RAT, LodaRAT and Meterpreter.
Exploited software
MITRE ATT&CK
Reporting
Splunk published a Windows endpoint analytic that detects suspicious child processes launched by consent.exe, a behavior strongly associated with User Account Control (UAC) bypass and privilege escalation. Because consent.exe normally displays the UAC elevation prompt rather than spawning executables, the detection treats such process creation as anomalous, excluding WerFault.exe as a known crash-related exception. The analytic maps to MITRE ATT&CK techniques T1548.002, T1068, and T1059, and is designed for telemetry from Sysmon, Windows Security Event ID 4688, and CrowdStrike ProcessRollup2 data normalized into Splunk's Endpoint data model. The release aligns with MITRE ATT&CK documentation showing UAC bypass remains a widely used post-compromise technique across ransomware operators, commodity malware, and state-linked intrusion groups. ATT&CK lists methods including COM abuse through CMSTPLUA, scheduled task abuse such as SilentCleanup, registry hijacks involving ms-settings and mscfile, and abuse of trusted Windows binaries including fodhelper.exe, eventvwr.exe, and sdclt.exe. Splunk also published supporting attack simulation data for suspicious child processes of consent.exe, giving defenders a way to test visibility for this privilege-escalation pattern, although the analytic is disabled by default and generates intermediate risk events rather than direct notable alerts.
Elastic Endpoint Security added kernel-driver-derived file and registry telemetry to detect access to sensitive credential stores, including browser data, Windows SAM and LSA secrets, cached domain credentials, credential files, and Windows Credential Manager. Its behavior protections can block high-confidence credential-theft activity associated with tools and malware such as Mimikatz, LaZagne, AgentTesla, FormBook, and Poulight Stealer; KQL and EQL hunting can also identify processes opening multiple sensitive stores or SMB access following a network logon. Attackers commonly extract saved browser usernames, passwords, cookies, and session tokens from stores such as Chrome’s Login Data and Firefox’s key3.db, key4.db, and logins.json. They also dump Windows LSA secrets and cached domain credentials using utilities including Mimikatz, reg save, Impacket secretsdump.py, CrackMapExec, and gsecdump. Cached Windows credentials are generally stored as DCC2/MS-Cache v2 hashes and require offline cracking rather than pass-the-hash, while Linux Active Directory integrations may retain cached credentials in SSSD or Quest database files.
Researchers reported multiple financially motivated malware campaigns using SmokeLoader as a delivery mechanism for follow-on payloads including Gozi ISFB, ZLoader, Oski, AveMaria, Cobalt Strike, SystemBC, RecordBreaker, and the Laplas Clipper cryptocurrency hijacker. In one campaign set, attackers abused website contact forms and sent phishing lures posing as copyright complaints, directing victims to malicious documents hosted on legitimate services such as Google Drive. Talos found the initial payloads were wrapped in a shared crypter identified by the DOS-stub string "Salfram," indicating a common tooling layer across otherwise varied malware deliveries. The activity relied on evasive and modular infection chains designed to complicate detection and maximize monetization. The Salfram crypter used obfuscation methods including fake API calls, fragmented control flow, self-modifying code, and memory allocation through ZwAllocateVirtualMemory, while later-stage malware added persistence and theft capabilities. Cyble said Laplas Clipper monitored the clipboard for cryptocurrency wallet addresses, pulled regex patterns and replacement addresses from clipper[.]guru, and persisted by copying itself into %appdata% and creating a scheduled task that ran every minute. The combined use of phishing, legitimate hosting platforms, crypter-based obfuscation, and multi-payload delivery shows an adaptable criminal ecosystem built to steal credentials, proxy access, banking data, and cryptocurrency funds.
A long-running cyberespionage operation dubbed Bandidos used the Bandook remote access trojan to infiltrate corporate networks across Spanish-speaking Latin America, with roughly 90% of observed detections concentrated in Venezuela. The campaign, active since at least 2015, relied on phishing emails carrying PDF lures that directed victims to password-protected archives containing a Delphi dropper. That dropper injected Bandook into iexplore.exe through process hollowing, established persistence via Windows Registry changes, and connected to command-and-control servers over TCP. Researchers said the malware supported extensive surveillance and theft functions, including screenshot capture, webcam and microphone recording, USB data theft, and interception of Chrome credentials, while also downloading additional DLLs to expand capability. The 2021 variant showed notable evolution from earlier Bandook activity, including a shift from CAST-256 to GOST in the dropper, a reduced DLL set, and support for 132 commands. The infrastructure and tooling overlapped with previously documented Bandook-linked operations, including Operation Manul, Dark Caracal, and Check Point research, reinforcing the assessment that the operators were conducting sustained espionage against Venezuelan organizations in sectors such as manufacturing, construction, healthcare, software services, and retail.
Check Point Research reported that a newer Smokeloader variant introduced multiple changes to improve stealth, evasion, and persistence. The malware was observed bypassing userland hooks by loading a duplicate copy of ntdll.dll, adding anti-VM and anti-debugging checks, changing its URL decoding routine and network connection structure, and modifying persistence by using startup .lnk files followed by delayed scheduled-task creation. The activity was tied to a broader campaign that targeted trezor.io through FakeDNS redirection and used DDoS plugins while also delivering the Azorult infostealer from fileboard.live. Researchers said C2 naming patterns, reused RC4 keys, and historical overlap with Amadey, AveMaria, and ServHelper campaigns suggest the operator behind this Smokeloader activity may be TA505.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.