WmRAT is a C++ remote access trojan associated with the Bitter espionage group, also tracked as TA397. First observed in 2022 and still in operational use through 2025, it has been deployed in targeted espionage campaigns against government, defense, telecommunications, and other strategic-sector organizations, including victims in Turkey and Pakistan. The malware is used for intelligence collection and data theft as part of Bitter’s broader state-aligned collection activity.
WmRAT provides operators with a typical espionage-oriented RAT feature set. Documented capabilities include collection of host identifiers such as username and computer name, logical drive and directory enumeration, file upload and download, screenshot capture, geolocation retrieval, and execution of arbitrary commands through the Windows command interpreter and PowerShell. Additional observed functionality includes retrieval of file timestamps, disk-usage information, remote file stream writing, and file exfiltration. Its command-and-control protocol uses numerical commands, and variants have embedded and obfuscated C2 configuration data.
The malware has also shown persistence behavior on Windows through autorun mechanisms in the current user context. Some variants launch secondary processes as part of their startup chain. Anti-analysis and evasion behavior has been reported as well, including creation of junk threads and repeated sleep activity intended to generate noise and complicate analysis.
Observed delivery has been closely tied to Bitter’s spearphishing operations. In documented campaigns, WmRAT was delivered after phishing emails carrying malicious attachments or lures triggered staged execution chains involving scheduled tasks, scripts, MSI installers, or macro-enabled Office-related content. Operators have also manually deployed WmRAT during hands-on-keyboard intrusions after victim triage and host reconnaissance, indicating selective second-stage use against higher-value targets.
WmRAT is best characterized as a purpose-built Windows espionage RAT within Bitter’s malware ecosystem, alongside families such as MiyaRAT, BDarkRAT, MuuyDownloader, and ORPCBackdoor. Its recurring use across multiple campaigns, combined with code and behavioral consistency, indicates sustained development and operational reliance by the actor.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
This macro used the Windows command line (CMD) to download and execute a variant of WmRAT. ... the payload downloaded from fogomyart[.]com/vcswin.png is a new variant of WmRAT – a remote access trojan designed for intelligence gathering and data exfiltration.
only the subsequent issuance of wmrat and .net Trojans are very difficult to bypass the characteristics of the checking and killing function
27 distinct techniques documented for this family, organized by ATT&CK tactic.
The tactics of these groups have hardly changed much from 2019 to the present... but the phishing mode by casting a wide net can still affect government and enterprise customers to a certain extent.
EclecticIQ analysts observed that Bitter APT very likely targeted the Pakistan Telecommunication Company Limited (PTCL) workers in a spear phishing campaign... The malicious email, received on Wednesday, May 7, 2025, at 12:09 PM, contained an Internet Query (IQY) attachment with a malicious Excel macro.
The attack chain used... a shortcut (LNK) file that created a scheduled task on the target machine to pull down further payloads... the command then set up a scheduled task named “DsSvcCleanup”.
BDarkRAT includes standard RAT capabilities such as executing shell commands, downloading files, and managing files on the compromised system.
These commands are typically issued over the same C2 channel and can be executed on the victim machine using either PowerShell or the Windows command prompt.
This macro used the Windows command line (CMD) to download and execute a variant of WmRAT.
The attack chain used... a shortcut (LNK) file that created a scheduled task on the target machine to pull down further payloads... the command then set up a scheduled task named “DsSvcCleanup”.
EclecticIQ analysts reverse-engineered the WmRAT variant and discovered that its command-and-control (C2) server was hidden within the rdata section of the malware as an XOR-encrypted string.
The script... downloads a payload that is disguised as a PNG image file (vcswin.png)... The script reconstructs a valid PE file by crafting an MZ header in memory and appending it to the binary payload.
WmRAT also employs some kind of anti-analysis by creating a number of junk threads. The threads loop for 1000 times just to get basic machine information. This is possibly done to generate noise in the logs of the victim’s environment. It also frequently calls the Sleep function throughout the code as an evasion technique.
This scheduled task attempted to send target host information (username and computer name) with the curl utility every 17 minutes... GET hxxp://jacknwoods[.]com/jacds.php?jin=%computername%_%username%
According to reverse engineered sample (vcswin.png), analysts gathered list of WmRAT capabilities: Gathers username and hostname of the victim machine... Retrieves geolocation information... Retrieves file timestamps and disk usage information.
According to reverse engineered sample (vcswin.png), analysts gathered list of WmRAT capabilities: Enumerates logical drives and directory contents
WmRAT also employs some kind of anti-analysis by creating a number of junk threads. The threads loop for 1000 times just to get basic machine information. This is possibly done to generate noise in the logs of the victim’s environment. It also frequently calls the Sleep function throughout the code as an evasion technique.
EclecticIQ analysts observed that WmRAT communicates with a remote C2 server using HTTP GET requests over HTTPS (port 443).
20 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
C++ malware family used in an espionage intrusion against a Turkish defense-sector organization.
Remote access trojan used by Bitter/TA397 in targeting activity (Turkey noted) as part of an espionage-focused toolset.
wmRAT is a remote access trojan (RAT) deployed by TA397 for hands-on-keyboard access, enabling remote control and data exfiltration from victim systems.
A C++ RAT that decrypts strings including the C2 address, collects system information, and supports screenshot capture, file theft, and PowerShell execution. It also uses junk threads and frequent Sleep calls as anti-analysis or noise-generation techniques.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.