Skip to content

WarzoneRAT

Warzone RAT, also known as AveMaria, is a commodity Windows remote access trojan first seen in 2018 and widely used in cybercrime operations.

Profile source: Mallory opens in a new tab

WarzoneRAT

Family profile

Warzone RAT, also known as AveMaria, is a commodity Windows remote access trojan first seen in 2018 and widely used in cybercrime operations. It provides full remote access to compromised systems and supports interactive control through remote desktop functionality, including hidden VNC access to reduce user visibility. Reported capabilities include credential theft from web browsers and email clients, cookie theft, keylogging, webcam access, file and process management, remote shell execution, data exfiltration, and use of PowerShell to download additional content and execute commands. The malware has also been associated with privilege-escalation behavior through UAC bypass techniques, registry modification, and DLL injection into other processes, as well as defense evasion through disabling or weakening Windows Defender during elevation workflows. Warzone RAT has commonly been delivered through malicious email attachments that require victim interaction to execute, making phishing and spearphishing a frequent infection vector. It has been used by multiple criminal actors, including activity attributed to Scattered Spider, to steal credentials, cookies, and other information from compromised environments. In February 2024, an FBI-led international law enforcement operation disrupted infrastructure associated with the malware and arrested individuals accused of selling and supporting it.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Keylogging
  • Post Exploitation
  • Privilege Escalation
  • Process Injection
  • Session Hijacking

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 6, 2026
Last activity
Aug 13, 2026
Feed role
C2 / Distribution
Host form
12 IP / 50 hostnames

Leading locations

  • US42
  • DE7
  • IE5
  • RU3
  • LU2
  • NL1
  • PL1
  • VN1

Leading providers

  • Amazon.com, Inc.17
  • Amazon.com, Inc.16
  • FEMO IT SOLUTIONS LIMITED5
  • Cloudflare, Inc.3
  • Google LLC3
  • Akamai Connected Cloud2

Infrastructure traits

  • Hosting 61
  • Vpn 5
  • Anycast 4

Samples

Recent associated samples

Reported operators

Threat actors

2 named in public reporting
Scattered Spider

Apart from the above legitimate tools used for malicious purposes, Scattered Spider also conducts phishing attacks to install malware like the WarZone RAT, Raccoon Stealer, and Vidar Stealer, to steal from compromised systems login credentials, cookies, and other data useful in the attack.

YoroTrooper

For remote access, YoroTrooper has also deployed commodity malware, such as AveMaria/Warzone RAT, LodaRAT and Meterpreter.

Exploited software

Vulnerabilities linked to WarzoneRAT

1 CVEs

MITRE ATT&CK

WarzoneRAT in ATT&CK

71 distinct techniques

Techniques

71 techniques
T1566.001 Spearphishing Attachment T1204 User Execution T1543 Create or Modify System Process T1082 System Information Discovery T1548.002 Bypass User Account Control T1547.001 Registry Run Keys / Startup Folder T1112 Modify Registry T1189 Drive-by Compromise T1055 Process Injection T1622 Debugger Evasion T1497.001 System Checks T1222 File and Directory Permissions Modification T1566 Phishing T1614.001 System Language Discovery T1548 Abuse Elevation Control Mechanism T1620 Reflective Code Loading T1219 Remote Access Tools T1071 Application Layer Protocol T1056.001 Keylogging T1083 File and Directory Discovery T1204.002 Malicious File T1125 Video Capture T1140 Deobfuscate/Decode Files or Information T1564.003 Hidden Window T1497 Virtualization/Sandbox Evasion T1059.003 Windows Command Shell T1562 Impair Defenses T1036 Masquerading T1053.005 Scheduled Task T1057 Process Discovery T1071.001 Web Protocols T1555 Credentials from Password Stores T1561 Disk Wipe T1564.004 NTFS File Attributes T1070.004 File Deletion T1021.001 Remote Desktop Protocol T1553.005 Mark-of-the-Web Bypass T1129 Shared Modules T1056.003 Web Portal Capture T1005 Data from Local System T1105 Ingress Tool Transfer T1059.001 PowerShell T1041 Exfiltration Over C2 Channel T1555.003 Credentials from Web Browsers T1539 Steal Web Session Cookie T1055.001 Dynamic-link Library Injection T1113 Screen Capture T1090 Proxy T1562.009 Safe Mode Boot T1136 Create Account T1033 System Owner/User Discovery T1115 Clipboard Data T1560 Archive Collected Data T1489 Service Stop T1564.002 Hidden Users T1529 System Shutdown/Reboot T1123 Audio Capture T1221 Template Injection T1014 Rootkit T1564 Hide Artifacts T1047 Windows Management Instrumentation T1095 Non-Application Layer Protocol T1090.001 Internal Proxy T1562.001 Disable or Modify Tools T1573.001 Symmetric Cryptography T1106 Native API T1021.005 VNC T1546.015 Component Object Model Hijacking T1204.001 Malicious Link T1566.003 Spearphishing via Service T1027 Obfuscated Files or Information

Reporting

Research mentioning WarzoneRAT

Jul 30
Splunk Research

Detection: Windows Suspicious Child Process of Consent.EXE | Splunk Security Content

Splunk published a Windows endpoint analytic that detects suspicious child processes launched by consent.exe, a behavior strongly associated with User Account Control (UAC) bypass and privilege escalation. Because consent.exe normally displays the UAC elevation prompt rather than spawning executables, the detection treats such process creation as anomalous, excluding WerFault.exe as a known crash-related exception. The analytic maps to MITRE ATT&CK techniques T1548.002, T1068, and T1059, and is designed for telemetry from Sysmon, Windows Security Event ID 4688, and CrowdStrike ProcessRollup2 data normalized into Splunk's Endpoint data model. The release aligns with MITRE ATT&CK documentation showing UAC bypass remains a widely used post-compromise technique across ransomware operators, commodity malware, and state-linked intrusion groups. ATT&CK lists methods including COM abuse through CMSTPLUA, scheduled task abuse such as SilentCleanup, registry hijacks involving ms-settings and mscfile, and abuse of trusted Windows binaries including fodhelper.exe, eventvwr.exe, and sdclt.exe. Splunk also published supporting attack simulation data for suspicious child processes of consent.exe, giving defenders a way to test visibility for this privilege-escalation pattern, although the analytic is disabled by default and generates intermediate risk events rather than direct notable alerts.

Jul 22
Splunk Research

Windows Suspicious Child Of Consent.exe | Splunk Security Content

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.