CABINETRAT is a Windows backdoor/remote access trojan (RAT) written in C and delivered as shellcode. It has been used in targeted espionage activity, including a September 2025 campaign attributed by CERT-UA to UAC-0245 against Ukrainian targets, including members of the Ukrainian Officers Union, with reporting also describing targeting of sensitive sectors such as government and telecom. In the observed campaign, attackers distributed malicious Microsoft Excel XLL add-ins via Signal, including ZIP archives such as "500.zip" disguised as border- or detention-related documents. The XLL add-in abuses Excel add-in loading, including xlAutoOpen, drops components such as an EXE in the Windows Startup folder, an XLL loader in Excel startup locations including %APPDATA%\Microsoft\Excel\XLSTART\ and/or XLSTART-related paths, launches EXCEL.EXE hidden with /e or /embed, and extracts CABINETRAT shellcode from a PNG file such as "Office.png".
CABINETRAT is designed for stealthy, long-term access and follow-on collection. Reported capabilities include gathering operating system and installed-program information, broader host reconnaissance such as memory, processor, disk, and privilege information, enumerating directories, listing, uploading, downloading, deleting, and exfiltrating files, executing commands, and capturing screenshots. Communications are over TCP C2; one report states it probes ports 18700, 42831, 20046, and 33976 in a port-knock-like sequence and uses a handshake in which the client sends "Ninja" and the server replies "Bonjour." Messages may be compressed with MSZIP and split when large.
Persistence mechanisms directly described in the content include Windows Registry Run keys, scheduled tasks configured for recurring execution, and copies placed in the All-Users Startup folder or user Startup folder. CABINETRAT-related tradecraft also includes querying registry keys such as HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\EXCEL.EXE and HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows, and clearing Excel Resiliency DisabledItems registry entries to re-enable malicious add-ins.
Anti-analysis and evasion behaviors mentioned in the content include checks for at least two CPU cores and at least 3 GB of RAM, detection of virtualization platforms including VMware, VirtualBox, Xen, QEMU, Parallels, Hyper-V, and Virtual PC, checking the PEB BeingDebugged flag, validating that the user SID does not end with "500," inspecting Kernel32.dll for Wine-related inconsistencies, and looking for VM-associated display artifacts.
High-confidence artifacts and indicators mentioned in the content include filenames such as "UBD Request.xll," "recept_ruslana_nekitenko.xll," "dodatok.xll," "BasicExcelMath.xll," and "Office.png"; staging under %LOCALAPPDATA%\Microsoft\Office; execution via hidden Excel; and suspicious Office-spawned schtasks.exe or reg.exe activity. Attribution beyond UAC-0245 is described as unclear in the content, though one source notes analysts flagged possible connections to East Asia-origin tooling and infrastructure.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Their tool of choice is called CABINETRAT ... Once active, CABINETRAT operates as a RAT (Remote Access Trojan), acting as a hidden remote control that lets operators reach into the system.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
A Scheduled Task: Using the Windows Task Scheduler, the malware adds its own recurring job set to execute every hour, on repeat. If the process is ever terminated, the system schedule simply relaunches it (MITRE ATT&CK T1053.005).
A Registry Run Key: The malware injects a new line into the Windows registry database under the Run keys, ensuring it initializes immediately at system startup (MITRE ATT&CK T1547.001). | The Startup Folder: Dropping a copy of the malware directly into the All-Users Startup folder provides a third layer of redundancy to guarantee execution.
A Scheduled Task: Using the Windows Task Scheduler, the malware adds its own recurring job set to execute every hour, on repeat. If the process is ever terminated, the system schedule simply relaunches it (MITRE ATT&CK T1053.005).
A Registry Run Key: The malware injects a new line into the Windows registry database under the Run keys, ensuring it initializes immediately at system startup (MITRE ATT&CK T1547.001). | The Startup Folder: Dropping a copy of the malware directly into the All-Users Startup folder provides a third layer of redundancy to guarantee execution.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote access trojan used for espionage that takes screenshots, performs host reconnaissance, exfiltrates files, and maintains persistent access through Excel XLSTART loading, scheduled tasks, registry Run keys, and the Startup folder.
Referenced as a backdoor used in targeted cyberattacks against the Ukrainian Defense Forces.
Windows-targeting malware used for stealthy access and long-term persistence. Observed delivery/execution via Excel XLL add-ins (shellcode execution), persistence via Startup folder, Registry Run keys, and scheduled tasks; performs host discovery and environment checks (WMI queries for RAM/CPU, admin group SID checks), and includes evasion (clearing Excel DisabledItems, Wine/VM/debugger detection). Also observed performing screen capture for collection.
"CABINETRAT Backdoor Scheduled Task and Hidden Excel Execution Detection [Windows Process Creation]"
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.