MiyaRAT
MiyaRAT is a custom remote access tool associated with the Bitter espionage group (also tracked as TA397). Reporting from Proofpoint and Threatray describes it as part of TA397’s evolution from basic downloaders to more advanced remote access tooling, alongside families such as MuuyDownloader, BDarkRAT, and WmRAT, and indicates it remained under active development as of 2025. MiyaRAT has been observed in campaigns between October 2024 and April 2025 targeting primarily government, diplomatic, and defense organizations, including entities linked to China, Pakistan, other Indian neighboring countries, and, in December 2024, targets in Turkey. TA397 commonly delivers malware through spear-phishing using spoofed or compromised diplomatic and government email accounts, with lures themed around diplomatic, military, trade, and government matters. In documented intrusions, TA397 used files or URLs that created scheduled tasks, then conducted hands-on-keyboard activity to enumerate victim systems and selectively deploy follow-on payloads. Proofpoint specifically reported finding MiyaRAT payloads on a TA397-controlled SMB share after operators mounted \72.18.215[.]1\tempy to retrieve payloads during a government-targeting intrusion. MiyaRAT was also referenced in prior TA397 activity involving manual deployment of wmRAT and MiyaRAT. High-confidence contextual indicators tied to the broader TA397 activity include scheduled-task-based staging, beaconing to PHP endpoints, transmission of victim computer name and username, frequent use of Let’s Encrypt certificates on staging infrastructure, and infrastructure and operator activity aligned with Indian Standard Time business hours.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Groups observed using it
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In December 2024, evidence emerged of the threat actor's targeting of Turkey using malware families such as WmRAT and MiyaRAT...
Techniques & procedures
4 distinct techniques documented for this family, organized by ATT&CK tactic.
Initial Access
1 technique"PLAYFULGHOST Delivered via Phishing and SEO Poisoning"; "Victims get infected via phishing emails"; "phishing campaign" (multiple entries)
Execution
1 techniquePersistence
1 techniquePrivilege Escalation
1 techniqueStealth
1 techniqueCommand and Control
1 technique"EAGERBEE ... deploy additional payloads"; "download and execute malware code"; "pull down further payloads"
Recent activity
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
C++ malware family used alongside WmRAT in an espionage intrusion against a Turkish defense-sector organization.
Remote access trojan used by Bitter/TA397 in targeting activity (Turkey noted) as part of an espionage-focused toolset.
Custom remote access trojan used by Bitter/TA397 as part of its more advanced tooling for targeted espionage intrusions.
MiyaRAT is a remote access trojan (RAT) used by TA397 for persistent access and espionage, allowing the threat actor to control infected systems and exfiltrate sensitive data.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.