RuRAT is a remote access trojan used to provide persistent remote control of compromised Windows systems. It has been observed delivered through targeted social-engineering operations in which a fake chat or messaging application acts as a decoy installer while a second stage deploys RuRAT for ongoing access. In separate espionage activity, it has also been used by the threat actor Curly COMrades as part of a broader toolset that includes credential-harvesting utilities, tunneling tools, and custom implants.
Operationally, RuRAT is used to establish persistent remote access after initial compromise, enabling attackers to control the host and support follow-on objectives such as searching for sensitive information, harvesting credentials through companion tooling, and using the infected system as a foothold for lateral movement. Reporting also characterizes RuRAT as a legitimate remote monitoring and management program repurposed for malicious use, which is consistent with its role as a dual-use remote administration utility in intrusion sets.
Observed targeting linked to RuRAT includes limited spearphishing activity and broader cyber-espionage operations affecting government, judicial, media, and energy-related organizations in Eastern Europe, particularly Georgia and Moldova. Its use alongside stealth-focused tradecraft and other remote-access and proxying tools indicates a role in maintaining durable operator access within victim environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
RuRat is used by Curly COMrades for persistent remote access to compromised systems.
RuRat is a legitimate RMM tool abused by threat actors for persistent remote access to compromised systems.
RuRAT is installed via the fake Vuxner Chat/Trillian lure and provides remote access to the victim device, enabling attackers to gain initial access, take control of the host, search for credentials and sensitive data, and potentially move laterally in a network.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.