RATicate is an unidentified cybercriminal threat group associated with multiple malspam campaigns active from late 2019 into early 2020. The actor is known for delivering commodity remote-access trojans and information stealers through multi-stage NSIS-based installer chains, with observed final payloads including Lokibot, Betabot, Formbook, AgentTesla, NetWire, Bladabindi, BlackRAT, and Remcos. Activity attributed to the group shows a consistent loader architecture, similar packing logic, and recurring infrastructure patterns across distinct campaign waves, indicating a single operator or closely coordinated cluster. RATicate’s operations relied on email-based initial access using lure documents or installer attachments, including later pandemic-themed social engineering. The group’s NSIS installers abused the System.dll plugin to invoke a malicious loader DLL, decrypt embedded shellcode and additional stages from encrypted data, and ultimately inject the final malware into a spawned process using section-mapping techniques based on NtCreateSection and NtMapViewOfSection. The actor also used large collections of junk files inside installers to create analysis noise and complicate reverse engineering. Across analyzed samples, later-stage shellcode and loader behavior remained highly consistent even when the final malware family changed. Observed targeting focused on industrial organizations and critical-infrastructure-related businesses across Europe, the Middle East, and East Asia. Identified victims included organizations in Romania, Kuwait, South Korea, the United Kingdom, Switzerland, and Japan, with some repeat targeting across campaign waves. The group’s behavior is consistent with financially motivated malware delivery operations rather than espionage, using commodity RAT and infostealer payloads to obtain access and steal information. No high-confidence attribution to a nation state is established.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
11 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
9 malware families attributed to this actor across reporting.
4 additional families tracked in Mallory.
50 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.