VRat is a backdoor used in campaigns attributed to the Mysterious Elephant APT. The malware is described as a variant derived from the open-source RAT vxRat, and is referred to as "VRat" based on a PDB string found in the sample. In the reported 2025 campaign, Mysterious Elephant targeted government and foreign affairs entities in the Asia-Pacific region, with a strong focus on South Asia, including Pakistan, Bangladesh, Afghanistan, Nepal, and Sri Lanka. Initial access in these operations involved spear-phishing emails, exploit kits, and malicious documents, after which PowerShell-based staging and persistence mechanisms were used.
VRat was embedded within MemLoader Edge, a malicious loader that used encryption and evasion techniques. MemLoader Edge tested connectivity to bing.com on port 445 and altered its behavior if the connection succeeded. It decrypted an embedded PE by iterating through a 1016-byte array to identify XOR keys until the decrypted content matched the MZ\x90 header, then reflectively loaded the payload in memory. The decrypted PE was identified as vxRat-based VRat. The surrounding campaign emphasized stealth, in-memory execution, and anti-analysis behavior.
High-confidence associations in the source material link VRat specifically to Mysterious Elephant operations against government and diplomatic targets. The provided content does not enumerate VRat-specific command capabilities or standalone indicators of compromise beyond its vxRat lineage, its naming via PDB string, and its delivery through MemLoader Edge.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
VRat is a variant of the open-source vxRat remote access trojan, used for remote control and data exfiltration.
RAT/backdoor payload (vxRat-derived) embedded and delivered by MemLoader Edge via in-memory reflective loading after XOR decryption.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.