Last seven days
- First activity
- Aug 6, 2026
- Last activity
- Aug 13, 2026
- Feed role
- C2 / Distribution
- Host form
- 12 IP / 50 hostnames
Warzone RAT, also known as AveMaria, is a commodity Windows remote access trojan first seen in 2018 and widely used in cybercrime operations.
Profile source: Mallory opens in a new tabWarzoneRAT
Warzone RAT, also known as AveMaria, is a commodity Windows remote access trojan first seen in 2018 and widely used in cybercrime operations. It provides full remote access to compromised systems and supports interactive control through remote desktop functionality, including hidden VNC access to reduce user visibility. Reported capabilities include credential theft from web browsers and email clients, cookie theft, keylogging, webcam access, file and process management, remote shell execution, data exfiltration, and use of PowerShell to download additional content and execute commands. The malware has also been associated with privilege-escalation behavior through UAC bypass techniques, registry modification, and DLL injection into other processes, as well as defense evasion through disabling or weakening Windows Defender during elevation workflows. Warzone RAT has commonly been delivered through malicious email attachments that require victim interaction to execute, making phishing and spearphishing a frequent infection vector. It has been used by multiple criminal actors, including activity attributed to Scattered Spider, to steal credentials, cookies, and other information from compromised environments. In February 2024, an FBI-led international law enforcement operation disrupted infrastructure associated with the malware and arrested individuals accused of selling and supporting it.
C2 tracking
Derp observations, rolling seven-day window
Samples
85aa108203f619c44f5c4c440447ef869995fca6a173b7def7e8fa4dca325323 bcc860ec249fd58a0e34e7469f9da913a86b3d58951c0ff60d6fa8df5104ce37 d1e92aca80c9beb0b9188d358c73b165c40b361e7ecfafd0acfbeceed79b89fc ee7d5d6fd490987b5000f6b8776c613d2f514aa26e7dc93667e54d0e524b7713 f9cfdb9ff0dec18360d420931961198080c4d009a5f8711df237f0fdbbe07a33 01be18e5bd3d04c79f8db21b72c06b84e724628e24f978a98aa86b4cb5b10499 067e4d534c2c4b0808b3e895d5df93f46fed2718984d5a61e13f2a01ac610215 2fcad226b17131da4274e1b9f8f31359bdd325c9568665f08fd1f6c5d06a23ce 4911b1593b03a4f312d8314762cd9e3b529fde33f34a61a4f2081f137529ef7c a835f1601b2834fbeb9a3b4b3156d0d0e5ddeac3d9ca0500f5cbfe832d6958b4 Reported operators
Apart from the above legitimate tools used for malicious purposes, Scattered Spider also conducts phishing attacks to install malware like the WarZone RAT, Raccoon Stealer, and Vidar Stealer, to steal from compromised systems login credentials, cookies, and other data useful in the attack.
For remote access, YoroTrooper has also deployed commodity malware, such as AveMaria/Warzone RAT, LodaRAT and Meterpreter.
Exploited software
MITRE ATT&CK
Reporting
Splunk published a Windows endpoint analytic that detects suspicious child processes launched by consent.exe, a behavior strongly associated with User Account Control (UAC) bypass and privilege escalation. Because consent.exe normally displays the UAC elevation prompt rather than spawning executables, the detection treats such process creation as anomalous, excluding WerFault.exe as a known crash-related exception. The analytic maps to MITRE ATT&CK techniques T1548.002, T1068, and T1059, and is designed for telemetry from Sysmon, Windows Security Event ID 4688, and CrowdStrike ProcessRollup2 data normalized into Splunk's Endpoint data model. The release aligns with MITRE ATT&CK documentation showing UAC bypass remains a widely used post-compromise technique across ransomware operators, commodity malware, and state-linked intrusion groups. ATT&CK lists methods including COM abuse through CMSTPLUA, scheduled task abuse such as SilentCleanup, registry hijacks involving ms-settings and mscfile, and abuse of trusted Windows binaries including fodhelper.exe, eventvwr.exe, and sdclt.exe. Splunk also published supporting attack simulation data for suspicious child processes of consent.exe, giving defenders a way to test visibility for this privilege-escalation pattern, although the analytic is disabled by default and generates intermediate risk events rather than direct notable alerts.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.