BDarkRAT is a .NET remote access trojan used by the Bitter espionage group, also tracked as TA397. First documented in 2019, it has remained in active use through 2025 as part of Bitter’s long-running cyber-espionage operations targeting primarily government, diplomatic, and defense-related organizations. The malware represents the group’s progression from earlier downloaders toward more capable interactive access tooling and appears to share development patterns with other Bitter malware families.
BDarkRAT performs initial host profiling by collecting system information and registering the victim with command-and-control infrastructure. It supports remote shell command execution, file download, and file-management operations on compromised systems. Newer variants observed in 2024 expanded functionality to include screen capture and PowerShell command execution, indicating continued development and adaptation. Reporting also notes that some code components likely derive from the older open-source DarkAgentRAT.
The malware is commonly delivered as a later-stage payload in Bitter intrusion chains rather than as a standalone initial-access tool. It has been observed deployed by Bitter downloaders including ArtraDownloader and MuuyDownloader, and in some campaigns operators manually delivered it during hands-on-keyboard activity after victim reconnaissance and target validation. Bitter’s broader operations are strongly associated with spearphishing-based intrusion chains using decoy documents and impersonation themes aligned with espionage objectives.
BDarkRAT targets Windows environments. Its development history shows iterative changes in command-and-control obfuscation and encryption, including variants that used AES-256-CBC with PBKDF2-derived key material for protected configuration data and later variants that altered encoding approaches while retaining core capabilities. Within Bitter’s arsenal, BDarkRAT functions as a persistent remote access capability supporting post-compromise control, reconnaissance, and follow-on tasking against selected espionage targets.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
BDarkRAT is a .NET RAT first discovered in 2019 that Bitter group continues to use today.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
BDarkRAT includes standard RAT capabilities such as executing shell commands, downloading files, and managing files on the compromised system.
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
.NET remote access trojan with capabilities including system information gathering, shell command execution, file download, and file management.
Custom remote access trojan used by Bitter/TA397 for remote control and post-compromise activity in targeted espionage operations.
BDarkRAT is a remote access trojan used by TA397 for espionage, providing persistent access and control over compromised systems.
A .NET remote access trojan that registers victims with collected system information and supports shell command execution, file download, file management, screen capture, and PowerShell execution depending on variant. It uses XOR-encrypted network packets and some variants encrypt the C2 address with AES-256-CBC.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.