RATicate
RATicate is an unidentified threat group dubbed by researchers based on multiple related malspam campaigns observed from November 2019 through January 2020. The group delivered NSIS installers that ultimately deployed RAT and infostealer payloads. Researchers identified five distinct campaign waves with similar packing code, a consistent multi-stage loader architecture, and overlapping command-and-control infrastructure, assessing them as the work of the same actors. Observed payload families included Lokibot, Betabot, Formbook, AgentTesla, Netwire, Bladabindi, Blackrat, and Remcos. The campaigns targeted industrial companies and critical-infrastructure-related organizations in Europe, the Middle East, and the Republic of Korea, with identified targets including organizations in Romania, Kuwait, South Korea, the UK, Switzerland, and Japan. Some victim overlap was noted across campaigns. RATicate’s NSIS installers abused the NSIS System.dll plugin to load an initial malicious DLL, decrypt embedded shellcode and additional loader stages from an encrypted data file, and ultimately inject the final payload into a child process, often cmd.exe, using NtCreateSection and NtMapViewOfSection. The installers also dropped numerous unused junk files to create analysis noise. Researchers identified 38 NSIS installer samples with highly similar characteristics, including identical junk files and a consistent loader architecture. Shellcode used for final payload decryption and injection was reported as binary-identical across analyzed samples. Observed lures included banking-themed emails, and later activity believed related to the same actor used COVID-19-themed lures. The report also notes a later shift toward other loaders and packers, including Visual Basic loaders and Guloader, while maintaining some of the same payload families and C2 patterns. Known alias: RATicate.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- industrial
- critical-infrastructure
Tradecraft
11 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
9 malware families attributed to this actor across reporting.
4 additional families tracked in Mallory.
Observables
50 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.