Atroposia is a malware-as-a-service remote access trojan (RAT) discovered by Varonis and marketed on underground forums as a turnkey, plug-and-play toolkit for low-skill affiliates. It is described as a modular RAT sold on a subscription basis, with cited pricing of $200 per month, $500 for three months, or $900 for six months. The malware combines persistent access, stealth, privilege escalation, data theft, and local vulnerability scanning in a single package.
Reported capabilities include encrypted command-and-control communications; persistence across reboots; Windows UAC bypass for privilege escalation; hidden remote desktop access via an "HRDP Connect" feature that creates a covert desktop session with little or no visible user indication; remote file browsing and execution through an Explorer-style file manager; credential theft; cryptocurrency wallet theft; chat file theft; real-time clipboard capture; bulk file collection using searches by extension or keyword; password-protected ZIP archiving for exfiltration; in-memory/fileless exfiltration techniques; DNS hijacking to redirect traffic to attacker-controlled infrastructure; and remote power controls such as shutdown, restart, and sleep. The built-in vulnerability scanner is described as auditing missing patches, unsafe settings, bugs, outdated VPN clients, and other exploitable weaknesses, and returning a score or report to help attackers prioritize follow-on exploitation and lateral movement.
The hidden desktop capability is highlighted as a distinctive feature because it allows attackers to surveil user activity, piggyback on authenticated sessions, open applications, view documents and email, manipulate workflows, and download or delete data without obvious signs to the victim. The DNS hijack functionality is described as enabling phishing, man-in-the-middle activity, fake updates, ad injection, malware injection, and possible DNS-based exfiltration.
The content associates Atroposia with the broader commoditization of cybercrime rather than a specific named threat actor. It is positioned as lowering the barrier to entry for cybercriminals by packaging advanced post-compromise functionality into an easy-to-use service. Reported infection or deployment vectors include phishing emails, malicious websites, exploitation of unpatched software, and post-compromise deployment as a backdoor. The content specifically notes concern for corporate environments because the malware can identify outdated VPN clients, insecure settings, and local privilege-escalation opportunities that support lateral movement.
High-confidence behavioral indicators mentioned in the content include encrypted command channels, covert or shadow-like remote desktop sessions, unexpected DNS record or host-level DNS changes, local vulnerability scanning activity, unusual clipboard monitoring, file search/compress/exfiltration behavior, and stealthy remote file operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
A grabber component looks for specific files, filtering them based on extension or a keyword, compresses the data into password-protected ZIP archives, and exfiltrates it using in-memory techniques to minimize traces.
a clipboard manager captures everything copied in real time (passwords, API keys, wallet addresses) and presents a history to the attacker
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote access trojan sold via subscription, providing remote control (hidden desktop), credential theft, and fileless attack capabilities via a web control panel.
A stealthy, feature-rich remote access trojan (RAT).
Atroposia is a stealthy, feature-rich Remote Access Trojan (RAT) designed for covert access and control of compromised systems.
A low-cost MaaS remote access trojan toolkit that provides covert remote desktop control (hidden/shadow sessions), encrypted C2, UAC bypass for privilege escalation, persistence, credential theft, vulnerability scanning, in-memory operation, bulk data exfiltration (file grabber + password-protected ZIP), clipboard monitoring, and host-level DNS hijacking to redirect traffic and enable phishing/MitM or fake updates.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.