Last seven days
- First activity
- Aug 1, 2026
- Last activity
- Aug 6, 2026
- Feed role
- C2 / Distribution
- Host form
- 13 IP / 0 hostnames
WarZone RAT, also known as AveMaria, is a commodity remote access trojan created in 2018 and widely used in cybercrime.
Profile source: Mallory opens in a new tabWarzoneRAT
WarZone RAT, also known as AveMaria, is a commodity remote access trojan created in 2018 and widely used in cybercrime. It has been described as enabling remote access to targeted organizations’ systems and has a long history of criminal use. Reported capabilities in the provided content include hidden remote desktop access via hVNC, control of an infected PC using RDP, webcam access, keylogging-related behavior, credential theft including passwords from numerous web browsers as well as Outlook and Thunderbird, cookie and password stealing, remote shell access, reverse proxying, file operations, process management, and exfiltration of collected victim data to its command-and-control server. The malware can use PowerShell to download files and execute commands, inject malicious DLLs into specific processes for privilege escalation, create the registry key HKCU\Software\Classes\Folder\shell\open\command during privilege escalation, and disarm Windows Defender during the UAC process to evade detection. The content also notes overlap in behavioral traces with other RATs such as njRAT, NanoCore, and NetWire, particularly around process injection, keylogging-related calls, and C2 traffic. Infection has been associated with malicious email attachments that require the victim to open the attachment for execution. The malware has also been referenced in Scattered Spider activity, where phishing attacks were used to install WarZone RAT alongside other stealers to obtain credentials, cookies, and other useful data. A 2024 FBI-led law enforcement action dismantled infrastructure associated with the malware’s operation, seized domains including warzone.ws, and arrested individuals allegedly involved in its proliferation and customer support.
C2 tracking
Derp observations, rolling seven-day window
Samples
2fcad226b17131da4274e1b9f8f31359bdd325c9568665f08fd1f6c5d06a23ce 30955adfb864533f1d6a46b25f02aa79c5c5891d0b536eb9da9d33bcaa1061db 4e5cc8cb98584335400d00f0a0803c3e0202761f3fbe50bcab3858a80df255e1 7fe76ccceaec33d07e90e96ac144be83ed622c8af8b134d7429020e476cf4716 8e2b78e7c586e36dc3b27c78466fad735f86cdd9b4e7ecbc4c650d934a9a176b b20f39fc00d242e706b6c30367ad811c676e0575050a4ec2f30104b696944b49 b7a06c7dd0943016ee68b5c14ec8a20578df56f9d9fa5f6ea73df6daa5211c07 d00a0806b145423c459a4df53471965dc36f82ec5d5a5d4d108e0a7a1ce09d7b e940830a9e6aa1ca42e80230d076fbc2a7a2ff5c715cc9fb49a061c532562f6f f270a80b90acb4302bb29b2f4c7436f6d7eedc4738ca63351f59f22bd59ce28d Reported operators
Apart from the above legitimate tools used for malicious purposes, Scattered Spider also conducts phishing attacks to install malware like the WarZone RAT, Raccoon Stealer, and Vidar Stealer, to steal from compromised systems login credentials, cookies, and other data useful in the attack.
For remote access, YoroTrooper has also deployed commodity malware, such as AveMaria/Warzone RAT, LodaRAT and Meterpreter.
Exploited software
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.