Last seven days
- First activity
- Jul 14, 2026
- Last activity
- Jul 21, 2026
- Feed role
- C2 / Distribution
- Host form
- 37 IP / 10 hostnames
WarZone RAT, also known as AveMaria, is a commodity remote access trojan created in 2018 and widely used in cybercrime.
Profile source: Mallory opens in a new tabWarzoneRAT
WarZone RAT, also known as AveMaria, is a commodity remote access trojan created in 2018 and widely used in cybercrime. It has been described as enabling remote access to targeted organizationsβ systems and has a long history of criminal use. Reported capabilities in the provided content include hidden remote desktop access via hVNC, control of an infected PC using RDP, webcam access, keylogging-related behavior, credential theft including passwords from numerous web browsers as well as Outlook and Thunderbird, cookie and password stealing, remote shell access, reverse proxying, file operations, process management, and exfiltration of collected victim data to its command-and-control server. The malware can use PowerShell to download files and execute commands, inject malicious DLLs into specific processes for privilege escalation, create the registry key HKCU\Software\Classes\Folder\shell\open\command during privilege escalation, and disarm Windows Defender during the UAC process to evade detection. The content also notes overlap in behavioral traces with other RATs such as njRAT, NanoCore, and NetWire, particularly around process injection, keylogging-related calls, and C2 traffic. Infection has been associated with malicious email attachments that require the victim to open the attachment for execution. The malware has also been referenced in Scattered Spider activity, where phishing attacks were used to install WarZone RAT alongside other stealers to obtain credentials, cookies, and other useful data. A 2024 FBI-led law enforcement action dismantled infrastructure associated with the malwareβs operation, seized domains including warzone.ws, and arrested individuals allegedly involved in its proliferation and customer support.
C2 tracking
Derp observations, rolling seven-day window
Samples
27dc2e511f4da03bc10b975156996133c8654defc24d40b829ff7d955be4e2ce 2e74827318235a497133219963a2205cd8d7779a195ec67d740d825599210932 5594d4a2153e25d5de0de21bc958e1d11a341679ea2fec2123567fa3547c7847 7ef34bf0c59089432586e8847b5a8d7439a28ed3aca3254fab49ef13723be65e c4617e465670873ca7de2d8898e8c349d8189b86561fc5b8996c4d8bab251801 08769871094b040c53079550c0568a201b82667c9924d3b2bd8c4d791d0e34a2 9679eba64a2a1ae1befaf601c89a4f93f261b69b2a9ce43d5574410d38f3ada8 b33129d9282053a29bff59f9354314fc6bfd0b69078ac44bd05274815185c125 ebebecd071c4f37722c5abcf1c928b0ca03039b9e77d0b839602358d3a822ef7 edd2351fe3fe14eb4d8b7bf89369354951919bae11f97278d78da35727c0028f Reported operators
Apart from the above legitimate tools used for malicious purposes, Scattered Spider also conducts phishing attacks to install malware like the WarZone RAT, Raccoon Stealer, and Vidar Stealer, to steal from compromised systems login credentials, cookies, and other data useful in the attack.
For remote access, YoroTrooper has also deployed commodity malware, such as AveMaria/Warzone RAT, LodaRAT and Meterpreter.
Exploited software
MITRE ATT&CK
Reporting
A group of remote access trojans, among them WarZoneRAT, njrat, nanocore, and netwire, overlap on process injection, keylogging-related calls, and command-and-control traffic.
Associated Analytic Story Warzone RAT
Associated Analytic Story ... Warzone RAT
Associated Analytic Story ... Warzone RAT
Associated Analytic Story Earth Alux ... Qakbot ... Warzone RAT ... Water Gamayun
Akande bought licenses for the Warzone remote-access trojan malware ... He then sent phishing emails ... directed recipients to a Dropbox link ... that, when clicked, silently installed the malware on their systems.
Officials said Akande also advanced the scheme by sending phishing emails to five Massachusetts-based tax preparation firms that were designed to trick employees into downloading remote access trojan malware, including Warzone RAT.
The emails purported to be from a prospective client seeking the tax preparation firmsβ services but in truth were used to trick the firms into downloading remote access trojan malicious software (RAT malware), including malware known as Warzone RAT.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.