njRAT, also known as Bladabindi, is a Windows remote-access trojan that provides interactive control of compromised hosts. It supports command-shell access, file transfer and modification, process and Registry manipulation, desktop monitoring, screenshot capture, webcam access, and keystroke logging. njRAT can steal browser credentials and cryptocurrency-related data, and has functionality for host and process reconnaissance. It has used Base64-encoded command-and-control communications and has established persistence through auto-run Registry mechanisms; some variants use AutoIt compilation after delivery. njRAT has been distributed in trojanized software, including fake game-download campaigns promoted through search-result poisoning, torrent sites, gaming forums, and social media. It has also appeared in staged delivery chains involving the YIPPHB dropper. The malware has been used or acquired by threat actors including Aquatic Panda and APT-C-36 (Blind Eagle).
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
스피어 피싱 이메일에 첨부되어 있던 파일은 RAR 압축 확장자를 가지고 있으며 ... 'CVE-2018-20250' 취약점을 사용했습니다. ... 'CVE-2018-20250' 취약점에 의해 시작 프로그램 경로(Startup)에 'ekrnview.exe' 악성 바이너리가 생성되도록 구성되어 있습니다. | ESRC에서는 해당 악성코드 (njRAT) 와 관련된 상세 내용과 인텔리전스 리포트를 '쓰렛 인사이드(Threat Inside)' 서비스를 통해 자세히 제공할 예정입니다.
Threat Actors (TAs) leveraging a Remote Code Execution (RCE) vulnerability, identified as CVE-2023-38831, to deliver their payload on compromised systems... The aforementioned vulnerability allows the WinRAR application to extract and execute the malicious script when a user tries to open a benign file within the archive. | We have also observed a YouTube video providing instructions on constructing an njRAT binary using a builder and utilizing the CVE-2023-38831 vulnerability to generate malicious WinRAR files.
When analyzing the organization’s CVE-2017-11882 exploit document, we found that the way to bypass the shellcode length limitation is similar to that used by the APT organization TA505... Unlike most previous CVE-2017-11882 exploits, Bayworld uses malicious code in xlsx files.
Associated Analytic Story ... NjRAT
the attachment was a weaponized RTF document utilizing CVE-2012-0158 to drop an embedded, encoded portable executable (PE)... In multiple lure documents, Type: Exploit, CVE-2012-0158, Embedded Payload. | This site is likely operated by the same actor(s) that carried out the previously discussed attacks on Indian embassy officials based on shared C&C infrastructure... lure Indian military officials into becoming infected with MSIL/Crimson, njRAT, and possibly other malicious tools.
Windows Office Product Spawned Uncommon Process ... CVE-2023-21716 Word RTF Heap Corruption, CVE-2023-36884 Office and Windows HTML RCE Vulnerability ...
26 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“In the past, we have observed that APT-C-36 makes use of RATs such as: njRAT ...”
к доменам хак-группы обращались более 31 000 образцов вредоносов, включая Quasar RAT, AsyncRAT, DCRat, NanoCore, Remcos RAT и njRAT
Aquatic Panda has acquired and used njRAT in its operations.
This group continued to use a variety of malware payloads including the addition of njRAT and Ozone RAT.
ESRC에서는 해당 악성코드 (njRAT) 와 관련된 상세 내용과 인텔리전스 리포트를 '쓰렛 인사이드(Threat Inside)' 서비스를 통해 자세히 제공할 예정입니다.
Summary njRAT (Bladabindi) is a .NET RAT (Remote Access Trojan) that allows attackers to take control of an infected machine.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
NJRAT provides extensive remote-access functionality, including command-shell access, keylogging, and browser credential theft.
818 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote-access trojan providing command-shell access, keylogging, camera and desktop surveillance, credential theft, file transfer, registry/process manipulation, screenshots, and cryptocurrency-related information theft. Observed samples created Windows Firewall rules and communicated with AWS-hosted IPs and an ngrok endpoint.
Remote-access malware represented among samples communicating with Sable Squirrel-controlled command-and-control infrastructure.
Remote-access trojan deployed by the fake GTA 6 installer. It provides remote control and surveillance capabilities, including keylogging, screenshot and webcam capture, file browsing, and browser-data theft.
A remote-access trojan deployed by the fake GTA VI installer. It provides remote control and surveillance capabilities, including keylogging, screenshot and webcam capture, file browsing, and browser-data theft.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.