Skip to content

WarzoneRAT

Warzone RAT, also known as Ave Maria, is a Windows remote-access trojan offered through a malware-as-a-service model and also deployed as a staged payload in targeted intrusion chains.

Profile source: Mallory opens in a new tab

WarzoneRAT

Family profile

Warzone RAT, also known as Ave Maria, is a Windows remote-access trojan offered through a malware-as-a-service model and also deployed as a staged payload in targeted intrusion chains. It supports remote command execution, reverse-shell access, hidden VNC-based remote desktop control, webcam capture, keylogging, browser and email-client credential theft, file operations, and process enumeration and termination. Observed variants and delivery chains have used PowerShell, process injection and process hollowing, masquerading, hidden execution, scheduled-task or startup persistence, and Windows UAC-bypass techniques. Warzone RAT has been delivered through phishing and spear-phishing campaigns using malicious Office documents, archives, macros, JavaScript, and PowerShell loaders; COVID-19-themed spam exploiting CVE-2017-11882 has also distributed it. APT-C-36 has used Warzone RAT among other commodity RATs. Campaigns targeting Indian government employees and military personnel have delivered Warzone RAT using Indian government-themed lures and were assessed to resemble Transparent Tribe and SideCopy activity.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Keylogging
  • Persistence
  • Post Exploitation
  • Privilege Escalation
  • Process Injection
  • Reconnaissance

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 22, 2026
Last activity
Sep 27, 2026
Feed role
C2 / Distribution
Host form
4 IP / 83 hostnames

Leading locations

  • US61
  • IE14
  • DE3
  • RU3
  • NL2
  • FI1

Leading providers

  • Amazon.com, Inc.31
  • Amazon.com, Inc.29
  • Google LLC6
  • Akamai Connected Cloud2
  • Omegatech LTD2
  • Smart Technology LLC2

Infrastructure traits

  • Hosting 80
  • Anycast 2

Samples

Recent associated samples

Reported operators

Threat actors

6 named in public reporting
APT-C-36

“In the past, we have observed that APT-C-36 makes use of RATs such as: ... Warzone RAT ...”

Transparent Tribe

Cisco Talos recently discovered a malicious campaign targeting government employees and military personnel in the Indian sub-continent with two commercial and commodity RAT families known as NetwireRAT (aka NetwireRC) and WarzoneRAT (aka Ave Maria).

Water Basilisk

In some cases, the final stage PowerShell script contained up to seven various RATs. These are typically NjRat, BitRat, Nanocore RAT, QuasarRat, LimeRat, and Warzone.

DDGroup

To give an overview, here is a list of all observed tools and malware types the actor has been using in recent years: Warzone RAT / AveMaria RAT

Scattered Spider

Apart from the above legitimate tools used for malicious purposes, Scattered Spider also conducts phishing attacks to install malware like the WarZone RAT, Raccoon Stealer, and Vidar Stealer, to steal from compromised systems login credentials, cookies, and other data useful in the attack.

YoroTrooper

For remote access, YoroTrooper has also deployed commodity malware, such as AveMaria/Warzone RAT, LodaRAT and Meterpreter.

Exploited software

Vulnerabilities linked to WarzoneRAT

2 CVEs

MITRE ATT&CK

WarzoneRAT in ATT&CK

83 distinct techniques

Techniques

83 techniques
T1059.001 PowerShell T1059.005 Visual Basic T1555.003 Credentials from Web Browsers T1566 Phishing T1057 Process Discovery T1105 Ingress Tool Transfer T1082 System Information Discovery T1203 Exploitation for Client Execution T1564.003 Hidden Window T1548.002 Bypass User Account Control T1204.002 Malicious File T1059.007 JavaScript T1566.001 Spearphishing Attachment T1053.005 Scheduled Task T1036 Masquerading T1055.012 Process Hollowing T1005 Data from Local System T1070.004 File Deletion T1204 User Execution T1021.001 Remote Desktop Protocol T1125 Video Capture T1083 File and Directory Discovery T1056.001 Keylogging T1055 Process Injection T1566.002 Spearphishing Link T1059 Command and Scripting Interpreter T1555 Credentials from Password Stores T1113 Screen Capture T1219 Remote Access Tools T1574.001 DLL T1027 Obfuscated Files or Information T1568 Dynamic Resolution T1548 Abuse Elevation Control Mechanism T1071 Application Layer Protocol T1112 Modify Registry T1564.002 Hidden Users T1136 Create Account T1569.002 Service Execution T1104 Multi-Stage Channels T1140 Deobfuscate/Decode Files or Information T1620 Reflective Code Loading T1027.002 Software Packing T1547.001 Registry Run Keys / Startup Folder T1584 Compromise Infrastructure T1543 Create or Modify System Process T1189 Drive-by Compromise T1622 Debugger Evasion T1497.001 System Checks T1222 File and Directory Permissions Modification T1614.001 System Language Discovery T1497 Virtualization/Sandbox Evasion T1059.003 Windows Command Shell T1562 Impair Defenses T1071.001 Web Protocols T1561 Disk Wipe T1564.004 NTFS File Attributes T1553.005 Mark-of-the-Web Bypass T1129 Shared Modules T1056.003 Web Portal Capture T1041 Exfiltration Over C2 Channel T1539 Steal Web Session Cookie T1055.001 Dynamic-link Library Injection T1090 Proxy T1562.009 Safe Mode Boot T1033 System Owner/User Discovery T1115 Clipboard Data T1560 Archive Collected Data T1489 Service Stop T1529 System Shutdown/Reboot T1123 Audio Capture T1221 Template Injection T1014 Rootkit T1564 Hide Artifacts T1047 Windows Management Instrumentation T1095 Non-Application Layer Protocol T1090.001 Internal Proxy T1562.001 Disable or Modify Tools T1573.001 Symmetric Cryptography T1106 Native API T1021.005 VNC T1546.015 Component Object Model Hijacking T1204.001 Malicious Link T1566.003 Spearphishing via Service

Reporting

Research mentioning WarzoneRAT

Jul 30
Splunk Research

Detection: Windows Suspicious Child Process of Consent.EXE | Splunk Security Content

Splunk published a Windows endpoint analytic that detects suspicious child processes launched by consent.exe, a behavior strongly associated with User Account Control (UAC) bypass and privilege escalation. Because consent.exe normally displays the UAC elevation prompt rather than spawning executables, the detection treats such process creation as anomalous, excluding WerFault.exe as a known crash-related exception. The analytic maps to MITRE ATT&CK techniques T1548.002, T1068, and T1059, and is designed for telemetry from Sysmon, Windows Security Event ID 4688, and CrowdStrike ProcessRollup2 data normalized into Splunk's Endpoint data model. The release aligns with MITRE ATT&CK documentation showing UAC bypass remains a widely used post-compromise technique across ransomware operators, commodity malware, and state-linked intrusion groups. ATT&CK lists methods including COM abuse through CMSTPLUA, scheduled task abuse such as SilentCleanup, registry hijacks involving ms-settings and mscfile, and abuse of trusted Windows binaries including fodhelper.exe, eventvwr.exe, and sdclt.exe. Splunk also published supporting attack simulation data for suspicious child processes of consent.exe, giving defenders a way to test visibility for this privilege-escalation pattern, although the analytic is disabled by default and generates intermediate risk events rather than direct notable alerts.

Jul 22
Splunk Research

Windows Suspicious Child Of Consent.exe | Splunk Security Content

Mar 1
Elastic Security Labs

Detect Credential Access with Elastic Security | Elastic Security Labs

Elastic Endpoint Security added kernel-driver-derived file and registry telemetry to detect access to sensitive credential stores, including browser data, Windows SAM and LSA secrets, cached domain credentials, credential files, and Windows Credential Manager. Its behavior protections can block high-confidence credential-theft activity associated with tools and malware such as Mimikatz, LaZagne, AgentTesla, FormBook, and Poulight Stealer; KQL and EQL hunting can also identify processes opening multiple sensitive stores or SMB access following a network logon. Attackers commonly extract saved browser usernames, passwords, cookies, and session tokens from stores such as Chrome’s Login Data and Firefox’s key3.db, key4.db, and logins.json. They also dump Windows LSA secrets and cached domain credentials using utilities including Mimikatz, reg save, Impacket secretsdump.py, CrackMapExec, and gsecdump. Cached Windows credentials are generally stored as DCC2/MS-Cache v2 hashes and require offline cracking rather than pass-the-hash, while Linux Active Directory integrations may retain cached credentials in SSSD or Quest database files.

Nov 2
Cyble Blog Historic

Cyble - New Laplas Clipper Distributed Via SmokeLoader

Researchers reported multiple financially motivated malware campaigns using SmokeLoader as a delivery mechanism for follow-on payloads including Gozi ISFB, ZLoader, Oski, AveMaria, Cobalt Strike, SystemBC, RecordBreaker, and the Laplas Clipper cryptocurrency hijacker. In one campaign set, attackers abused website contact forms and sent phishing lures posing as copyright complaints, directing victims to malicious documents hosted on legitimate services such as Google Drive. Talos found the initial payloads were wrapped in a shared crypter identified by the DOS-stub string "Salfram," indicating a common tooling layer across otherwise varied malware deliveries. The activity relied on evasive and modular infection chains designed to complicate detection and maximize monetization. The Salfram crypter used obfuscation methods including fake API calls, fragmented control flow, self-modifying code, and memory allocation through ZwAllocateVirtualMemory, while later-stage malware added persistence and theft capabilities. Cyble said Laplas Clipper monitored the clipboard for cryptocurrency wallet addresses, pulled regex patterns and replacement addresses from clipper[.]guru, and persisted by copying itself into %appdata% and creating a scheduled task that ran every minute. The combined use of phishing, legitimate hosting platforms, crypter-based obfuscation, and multi-payload delivery shows an adaptable criminal ecosystem built to steal credentials, proxy access, banking data, and cryptocurrency funds.

Jul 7
Eset Welivesecurity

Bandidos at large: A spying campaign in Latin America

A long-running cyberespionage operation dubbed Bandidos used the Bandook remote access trojan to infiltrate corporate networks across Spanish-speaking Latin America, with roughly 90% of observed detections concentrated in Venezuela. The campaign, active since at least 2015, relied on phishing emails carrying PDF lures that directed victims to password-protected archives containing a Delphi dropper. That dropper injected Bandook into iexplore.exe through process hollowing, established persistence via Windows Registry changes, and connected to command-and-control servers over TCP. Researchers said the malware supported extensive surveillance and theft functions, including screenshot capture, webcam and microphone recording, USB data theft, and interception of Chrome credentials, while also downloading additional DLLs to expand capability. The 2021 variant showed notable evolution from earlier Bandook activity, including a shift from CAST-256 to GOST in the dropper, a reduced DLL set, and support for 132 commands. The infrastructure and tooling overlapped with previously documented Bandook-linked operations, including Operation Manul, Dark Caracal, and Check Point research, reinforcing the assessment that the operators were conducting sustained espionage against Venezuelan organizations in sectors such as manufacturing, construction, healthcare, software services, and retail.

Dec 17
Telekom

A new way to encrypt CC server URLs | Deutsche Telekom

Check Point Research reported that a newer Smokeloader variant introduced multiple changes to improve stealth, evasion, and persistence. The malware was observed bypassing userland hooks by loading a duplicate copy of ntdll.dll, adding anti-VM and anti-debugging checks, changing its URL decoding routine and network connection structure, and modifying persistence by using startup .lnk files followed by delayed scheduled-task creation. The activity was tied to a broader campaign that targeted trezor.io through FakeDNS redirection and used DDoS plugins while also delivering the Azorult infostealer from fileboard.live. Researchers said C2 naming patterns, reused RC4 keys, and historical overlap with Amadey, AveMaria, and ServHelper campaigns suggest the operator behind this Smokeloader activity may be TA505.

Sep 3
Talosintelligence Other

Salfram: Robbing the place without removing your name tag

Jul 9
Checkpoint Research

The 2019 Resurgence of Smokeloader - Check Point Research

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.