Skip to main content
Mallory
MalwareUsed by 1 actor

MiyaRAT

MiyaRAT is a custom remote access tool associated with the Bitter espionage group (also tracked as TA397). Reporting from Proofpoint and Threatray describes it as part of TA397’s evolution from basic downloaders to more advanced remote access tooling, alongside families such as MuuyDownloader, BDarkRAT, and WmRAT, and indicates it remained under active development as of 2025. MiyaRAT has been observed in campaigns between October 2024 and April 2025 targeting primarily government, diplomatic, and defense organizations, including entities linked to China, Pakistan, other Indian neighboring countries, and, in December 2024, targets in Turkey. TA397 commonly delivers malware through spear-phishing using spoofed or compromised diplomatic and government email accounts, with lures themed around diplomatic, military, trade, and government matters. In documented intrusions, TA397 used files or URLs that created scheduled tasks, then conducted hands-on-keyboard activity to enumerate victim systems and selectively deploy follow-on payloads. Proofpoint specifically reported finding MiyaRAT payloads on a TA397-controlled SMB share after operators mounted \72.18.215[.]1\tempy to retrieve payloads during a government-targeting intrusion. MiyaRAT was also referenced in prior TA397 activity involving manual deployment of wmRAT and MiyaRAT. High-confidence contextual indicators tied to the broader TA397 activity include scheduled-task-based staging, beaconing to PHP endpoints, transmission of victim computer name and username, frequent use of Let’s Encrypt certificates on staging infrastructure, and infrastructure and operator activity aligned with Indian Standard Time business hours.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
Bitter

In December 2024, evidence emerged of the threat actor's targeting of Turkey using malware families such as WmRAT and MiyaRAT...

via the hacker newsthehackernews.com
MITRE ATT&CK

Techniques & procedures

4 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

1 technique
T1566PhishingEvidence1

"PLAYFULGHOST Delivered via Phishing and SEO Poisoning"; "Victims get infected via phishing emails"; "phishing campaign" (multiple entries)

Execution

1 technique
T1053.005Scheduled TaskEvidence1

"created a scheduled task on the target machine to pull down further payloads"

Persistence

1 technique
T1053.005Scheduled TaskEvidence1

"created a scheduled task on the target machine to pull down further payloads"

T1053.005Scheduled TaskEvidence1

"created a scheduled task on the target machine to pull down further payloads"

Stealth

1 technique
T1564.004NTFS File AttributesEvidence1
TacticStealth

"used alternate data streams in a RAR archive"

T1105Ingress Tool TransferEvidence1

"EAGERBEE ... deploy additional payloads"; "download and execute malware code"; "pull down further payloads"

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution1

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping4

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.