BDarkRAT
BDarkRAT is a .NET trojan/remote access tool first documented in 2019. Reporting cited in the source material associates it with the Bitter threat actor, also tracked as TA397, a state-backed espionage group assessed as aligned with Indian government interests. Researchers describe Bitter’s tooling as having evolved from basic downloaders to more advanced remote access tools including MuuyDownloader, BDarkRAT, and MiyaRAT, with active development observed as of 2025.
High-confidence capabilities explicitly attributed to BDarkRAT include system information gathering, shell command execution, file downloading, and file management on compromised hosts. In observed Bitter operations, BDarkRAT was used as a final payload or follow-on payload after initial spear-phishing compromise and staging activity. Bitter commonly used spear-phishing emails, often impersonating government or diplomatic entities and leveraging compromised or spoofed diplomatic email accounts, to target a very small subset of victims.
The campaigns described targeted primarily government, diplomatic, and defense organizations, including entities linked to China, Pakistan, Bangladesh, Turkey, and other countries relevant to Indian geopolitical interests, with activity observed across Asia and Europe and some reporting noting South America. In one specifically described CHM-based campaign, Bitter used a scheduled task named MSTaskUI to beacon to utizviewstation[.]com and later manually delivered BDarkRAT. More broadly, researchers observed hands-on-keyboard activity in some Bitter intrusions, including host enumeration and selective deployment of additional payloads such as KugelBlitz and BDarkRAT.
The content does not provide standalone BDarkRAT-specific hashes, mutexes, registry keys, or additional unique indicators beyond its association with Bitter campaigns and the observed delivery context above.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Groups observed using it
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
...drop additional payloads like KugelBlitz and BDarkRAT, a .NET trojan that was first documented in 2019.
Recent activity
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
.NET remote access trojan with capabilities including system information gathering, shell command execution, file download, and file management.
Custom remote access trojan used by Bitter/TA397 for remote control and post-compromise activity in targeted espionage operations.
BDarkRAT is a remote access trojan used by TA397 for espionage, providing persistent access and control over compromised systems.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.