Skip to content
Malware family

WarzoneRAT

WarZone RAT, also known as AveMaria, is a commodity remote access trojan created in 2018 and widely used in cybercrime.

Profile source: Mallory opens in a new tab

WarzoneRAT

Family profile

WarZone RAT, also known as AveMaria, is a commodity remote access trojan created in 2018 and widely used in cybercrime. It has been described as enabling remote access to targeted organizations’ systems and has a long history of criminal use. Reported capabilities in the provided content include hidden remote desktop access via hVNC, control of an infected PC using RDP, webcam access, keylogging-related behavior, credential theft including passwords from numerous web browsers as well as Outlook and Thunderbird, cookie and password stealing, remote shell access, reverse proxying, file operations, process management, and exfiltration of collected victim data to its command-and-control server. The malware can use PowerShell to download files and execute commands, inject malicious DLLs into specific processes for privilege escalation, create the registry key HKCU\Software\Classes\Folder\shell\open\command during privilege escalation, and disarm Windows Defender during the UAC process to evade detection. The content also notes overlap in behavioral traces with other RATs such as njRAT, NanoCore, and NetWire, particularly around process injection, keylogging-related calls, and C2 traffic. Infection has been associated with malicious email attachments that require the victim to open the attachment for execution. The malware has also been referenced in Scattered Spider activity, where phishing attacks were used to install WarZone RAT alongside other stealers to obtain credentials, cookies, and other useful data. A 2024 FBI-led law enforcement action dismantled infrastructure associated with the malware’s operation, seized domains including warzone.ws, and arrested individuals allegedly involved in its proliferation and customer support.

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Jul 14, 2026
Last activity
Jul 21, 2026
Feed role
C2 / Distribution
Host form
37 IP / 10 hostnames

Leading locations

  • US11
  • DE10
  • HK9
  • LU6
  • NL3
  • GB2
  • PL2
  • ES1
  • TR1

Leading providers

  • Ghosty Networks LLC5
  • CTG Server Limited4
  • FEMO IT SOLUTIONS LIMITED4
  • Cloudflare, Inc.3
  • DigitalOcean, LLC3
  • HostPapa3

Infrastructure traits

  • Hosting 45
  • Anycast 3
  • Vpn 3
  • Proxy 1

Samples

Recent associated samples

Reported operators

Threat actors

2 named in public reporting
Scattered Spider

Apart from the above legitimate tools used for malicious purposes, Scattered Spider also conducts phishing attacks to install malware like the WarZone RAT, Raccoon Stealer, and Vidar Stealer, to steal from compromised systems login credentials, cookies, and other data useful in the attack.

YoroTrooper

For remote access, YoroTrooper has also deployed commodity malware, such as AveMaria/Warzone RAT, LodaRAT and Meterpreter.

Exploited software

Vulnerabilities linked to WarzoneRAT

1 CVEs

MITRE ATT&CK

WarzoneRAT in ATT&CK

70 distinct techniques

Techniques

70 techniques
T1082 System Information Discovery T1548.002 Bypass User Account Control T1547.001 Registry Run Keys / Startup Folder T1112 Modify Registry T1189 Drive-by Compromise T1055 Process Injection T1622 Debugger Evasion T1497.001 System Checks T1222 File and Directory Permissions Modification T1566 Phishing T1614.001 System Language Discovery T1548 Abuse Elevation Control Mechanism T1620 Reflective Code Loading T1219 Remote Access Tools T1071 Application Layer Protocol T1056.001 Keylogging T1083 File and Directory Discovery T1204.002 Malicious File T1125 Video Capture T1140 Deobfuscate/Decode Files or Information T1564.003 Hidden Window T1497 Virtualization/Sandbox Evasion T1059.003 Windows Command Shell T1562 Impair Defenses T1036 Masquerading T1053.005 Scheduled Task T1057 Process Discovery T1071.001 Web Protocols T1555 Credentials from Password Stores T1561 Disk Wipe T1564.004 NTFS File Attributes T1070.004 File Deletion T1021.001 Remote Desktop Protocol T1553.005 Mark-of-the-Web Bypass T1129 Shared Modules T1056.003 Web Portal Capture T1005 Data from Local System T1105 Ingress Tool Transfer T1059.001 PowerShell T1041 Exfiltration Over C2 Channel T1555.003 Credentials from Web Browsers T1566.001 Spearphishing Attachment T1539 Steal Web Session Cookie T1204 User Execution T1055.001 Dynamic-link Library Injection T1113 Screen Capture T1090 Proxy T1562.009 Safe Mode Boot T1136 Create Account T1033 System Owner/User Discovery T1115 Clipboard Data T1560 Archive Collected Data T1489 Service Stop T1564.002 Hidden Users T1529 System Shutdown/Reboot T1123 Audio Capture T1221 Template Injection T1014 Rootkit T1564 Hide Artifacts T1047 Windows Management Instrumentation T1095 Non-Application Layer Protocol T1090.001 Internal Proxy T1562.001 Disable or Modify Tools T1573.001 Symmetric Cryptography T1106 Native API T1021.005 VNC T1546.015 Component Object Model Hijacking T1204.001 Malicious Link T1566.003 Spearphishing via Service T1027 Obfuscated Files or Information

Reporting

Research mentioning WarzoneRAT

Jun 26
Help Net Security

A privacy-first take on local malware analysis - Help Net Security

A group of remote access trojans, among them WarZoneRAT, njrat, nanocore, and netwire, overlap on process injection, keylogging-related calls, and command-and-control traffic.

Feb 25
Splunk Research

Detection: CMD Carry Out String Command Parameter | Splunk Security Content

Associated Analytic Story Warzone RAT

Feb 25
Splunk Research

Detection: Windows Office Product Dropped Uncommon File | Splunk Security Content

Associated Analytic Story ... Warzone RAT

Feb 25
Splunk Research

Detection: Powershell Windows Defender Exclusion Commands | Splunk Security Content

Associated Analytic Story ... Warzone RAT

Feb 23
Splunk Research

Detection: Windows Process Injection Remote Thread | Splunk Security Content

Associated Analytic Story Earth Alux ... Qakbot ... Warzone RAT ... Water Gamayun

Feb 19
Bleeping Computer

Nigerian man gets eight years in prison for hacking tax firms

Akande bought licenses for the Warzone remote-access trojan malware ... He then sent phishing emails ... directed recipients to a Dropbox link ... that, when clicked, silently installed the malware on their systems.

Feb 18
Cyberscoop

Nigerian man sentenced to 8 years in prison for running phony tax refund scheme | CyberScoop

Officials said Akande also advanced the scheme by sending phishing emails to five Massachusetts-based tax preparation firms that were designed to trick employees into downloading remote access trojan malware, including Warzone RAT.

Feb 18
Data Breaches

Nigerian Man Sentenced to Eight Years in Prison for Computer Intrusion and Theft - DataBreaches.Net

The emails purported to be from a prospective client seeking the tax preparation firms’ services but in truth were used to trick the firms into downloading remote access trojan malicious software (RAT malware), including malware known as Warzone RAT.

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.