njRAT, also known as Bladabindi and sometimes associated with the njw0rm lineage, is a widely used Windows remote access Trojan that provides attackers with persistent unauthorized access to infected systems. It is a long-running commodity malware family frequently used by cybercriminals and also adopted by multiple intrusion sets and regional espionage actors, including operations linked to Aquatic Panda, Gamaredon, TA558, and campaigns associated with Transparent Tribe. It has remained prevalent for years because it is broadly available, easy to deploy, and supports a broad set of surveillance and remote-control functions.
njRAT is primarily used for interactive post-compromise control and victim monitoring. Documented capabilities include keylogging, screenshot capture, webcam access, microphone or audio capture, downloading and executing additional payloads, registry read and modification operations, current-user enumeration, and discovery of attached peripherals such as cameras and removable drives. It also uses encoded command-and-control traffic, including Base64-obfuscated communications, and has been observed leveraging PowerShell in conjunction with autorun registry-key persistence. These behaviors make it suitable both as a standalone RAT and as a staging platform for follow-on malware.
Observed delivery chains show njRAT being distributed through malicious Office documents with macros, archive-contained lure files, and exploit-bearing documents in spearphishing campaigns. In one analyzed chain, a malicious PowerPoint file triggered staged retrieval of additional components through obfuscated script intermediaries, ultimately delivering .NET payloads. In other campaigns, njRAT has been delivered through politically themed and military-themed lures targeting Indian diplomatic and military personnel, as well as through broader commodity malware distribution by email-focused actors.
njRAT is commonly deployed against Windows environments and has appeared in both opportunistic crimeware activity and targeted espionage operations. Its continued use alongside other commodity RATs such as AsyncRAT, DCRat, LimeRAT, Remcos, and XWorm reflects its role as a durable, low-cost access tool for surveillance, credential collection, and follow-on intrusion activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
the attachment was a weaponized RTF document utilizing CVE-2012-0158 to drop an embedded, encoded portable executable (PE)... In multiple lure documents, Type: Exploit, CVE-2012-0158, Embedded Payload. | This site is likely operated by the same actor(s) that carried out the previously discussed attacks on Indian embassy officials based on shared C&C infrastructure... lure Indian military officials into becoming infected with MSIL/Crimson, njRAT, and possibly other malicious tools.
Windows Office Product Spawned Uncommon Process ... CVE-2023-21716 Word RTF Heap Corruption, CVE-2023-36884 Office and Windows HTML RCE Vulnerability ...
9 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
the payloads riding on top of them (NjRAT, AsyncRAT, LimeRAT) have barely changed in years
The group has been observed using widely-available tools such as the Remote Access Trojan (RAT) called “njRAT”...
Aquatic Panda has acquired and used njRAT in its operations.
This site is likely operated by the same actor(s) that carried out the previously discussed attacks on Indian embassy officials based on shared C&C infrastructure... lure Indian military officials into becoming infected with MSIL/Crimson, njRAT, and possibly other malicious tools.
While the actor favors VenomRAT, TA558 also distributes other commodity malware including njRAT, Remcos RAT, and recently XWorm and PDQ Connect.
The top 10 of the RATs used in Nigerian BEC scams is formed by NetWire, DarkComet, NanoCore, LuminosityLink, Remcos, ImminentMonitor, NJRat, Quasar, Adwind, and Hworm.
35 distinct techniques documented for this family, organized by ATT&CK tactic.
Adversaries may buy, steal, or download malware that can be used during targeting. Malicious software can include payloads, droppers, post-compromise tools, backdoors, packers, and C2 protocols. Adversaries may acquire malware to support their operations, obtaining a means for maintaining control of remote machines, evading defenses, and executing post-compromise behaviors.
Proofpoint researchers discovered a malicious blogspot.com site... set up to lure Indian military officials into becoming infected with MSIL/Crimson, njRAT, and possibly other malicious tools.
The output of stage 3 contained a simple VBS obfuscated code with recognizable words such as ‘replace,’ ‘base64,’ ‘WScript,’ and ‘PowerShell,’ as marked in Figure 5.
During the 2016 Ukraine Electric Power Attack, Sandworm Team used the xp_cmdshell command in MS-SQL. During the 2025 Poland Wiper Attacks, the adversaries leveraged PsExec to run cmd.exe commands on multiple victim machines. Numerous malware families and groups are described as using cmd.exe, cmd /c, Windows command shell, or command-line interfaces to execute commands, payloads, reconnaissance, persistence, cleanup, and ransomware actions.
The output of stage 3 contained a simple VBS obfuscated code with recognizable words such as ‘replace,’ ‘base64,’ ‘WScript,’ and ‘PowerShell,’ as marked in Figure 5. | After noticing the presence of Macros within the file, the tool olevba was used to gain more insight into what those Macros are. It’s also noteworthy that this macro is configured under the ‘AutoOpen’ feature, which automatically executes macros or actions when a presentation is opened.
In this incident, the attachment was a weaponized RTF document utilizing CVE-2012-0158 to drop an embedded, encoded portable executable (PE).
By relying on basic social engineering – an attack technique that takes advantage of human traits such as curiosity, trust and greed in order to obtain confidential information or to have the victim perform a certain action – it is suffice to say that certain threat actors (both criminal and nation state) are exploiting these unprecedented times for various nefarious means.
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
The output of stage 3 contained a simple VBS obfuscated code... This variable contained a Base64-encoded string that needed to be decoded and reversed... Those two URLs contained two different obfuscated strings.
They started distributing malware under the guise of restriction bypass programs and injecting malicious code into existing programs.
A group of remote access trojans, among them WarZoneRAT, njrat, nanocore, and netwire, overlap on process injection, keylogging-related calls, and command-and-control traffic.
The content repeatedly describes threat actors and malware deleting files, tools, scripts, logs, droppers, staged data, and artifacts from compromised systems to cover tracks, remove evidence, or self-delete.
Several entries describe malware examining running processes to determine if a debugger, sandbox, virtual environment, or analysis/security tools are present, such as AsyncRAT checking for a debugger, RogueRobin enumerating Wireshark and Sysinternals processes, and P8RAT checking for processes associated with virtual environments.
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
The content repeatedly describes malware and threat actors querying, enumerating, opening, and reading Windows Registry keys and values, e.g., "APT41 queried registry values to determine items such as configured RDP ports and network configurations" and "Reg may be used to gather details from the Windows Registry of a local or remote system at the command-line interface."
The content repeatedly describes malware and threat actors collecting usernames, identifying logged-in users, running whoami/query user/quser, checking whether the current user is an administrator, enumerating user sessions, and gathering account details from compromised hosts.
The content repeatedly describes malware and threat actors obtaining lists of running processes, using utilities such as tasklist, ps, WMI, Get-Process, CreateToolhelp32Snapshot, EnumProcesses, and similar APIs/commands to enumerate active processes on victim systems.
The content is a long ATT&CK-style listing of malware and threat actors that collect host details such as OS version, hostname, architecture, CPU, memory, BIOS, language, and other basic system characteristics; examples include use of commands like systeminfo, ver, uname, sw_vers, and WMI queries.
The content repeatedly describes malware and threat actors listing files and directories, enumerating drives, searching for files by extension/name/path, retrieving file metadata, and browsing file systems (for example: "APT28 has used Forfiles to locate PDF, Excel, and Word documents during collection" and "cmd can be used to find files and directories with native functionality such as dir commands").
ADVSTORESHELL can list connected devices. APT28 uses a module to receive a notification every time a USB mass storage device is inserted into a victim. APT37 has a Bluetooth device harvester, which uses Windows Bluetooth APIs to find information on connected Bluetooth devices.
Several entries describe malware examining running processes to determine if a debugger, sandbox, virtual environment, or analysis/security tools are present, such as AsyncRAT checking for a debugger, RogueRobin enumerating Wireshark and Sysinternals processes, and P8RAT checking for processes associated with virtual environments.
The content repeatedly describes threat actors and malware collecting, stealing, identifying, copying, or staging files, documents, credentials, logs, databases, and other information from compromised hosts or local systems.
Within the debugger, many functions related to a Keylogger and the transmission of information over a socket were observed.
It is capable of keylogging, taking screenshots, and controlling the victim’s webcam and microphone.
Within the debugger, many functions related to a Keylogger and the transmission of information over a socket were observed... At this point, I decided to run the malware to extract network-related IOCs.
The content repeatedly describes threat actors and malware using HTTP and HTTPS for command and control, such as: "Sandworm Team used BlackEnergy to communicate between compromised hosts and their command-and-control servers via HTTP post requests."
It was observed that this macro contains a suspicious URL linking to Pastebin... This initial URL redirected to another URL, which contained another payload... Those two URLs contained two different obfuscated strings.
ADVSTORESHELL exfiltrates data over the same channel used for C2... Agrius exfiltrated staged data using tools such as Putty and WinSCP, communicating with command and control servers... numerous malware and groups sent victim data, files, credentials, or host information over existing C2 channels.
155 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
156 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Commodity remote access trojan cited as part of Blind Eagle's long-running malware playbook.
NjRAT is only mentioned as an example of other malware previously associated with infrastructure reputation tied to the resolved IP; it is not the malware family under analysis in this report.
A .NET remote access trojan family referenced as an example of malware using Assembly.Load() for in-memory assembly loading.
A remote access trojan associated here with process injection, keylogging-related calls, and command-and-control traffic.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.