Atroposia RAT is a modular malware-as-a-service remote access trojan offered on a subscription model, reportedly priced at about $200 per month, with multi-month discounts also advertised. Reporting cited in the content describes it as lowering the barrier to entry for cybercrime by providing advanced RAT capabilities through a SaaS-like offering.
High-confidence capabilities mentioned in the content include persistence, data exfiltration, encrypted command-and-control communications, Windows User Account Control evasion that can enable privilege escalation, remote file management via an Explorer-like file manager, credential and data theft through a stealer module, clipboard monitoring/management, host-level DNS hijacking, hidden desktop control, and fileless attack support. The malware also includes an HRDP Connect Module that enables stealthy interaction with the victim system, including opening applications, documents, and emails. Its built-in local vulnerability scanner identifies incomplete patches and misconfigurations to help attackers prioritize exploitation.
The DNS hijack functionality is described as facilitating covert routing to attacker-controlled servers and supporting man-in-the-middle, phishing, and malware delivery activity. Infection vector details are not fully specified in the provided content, but the reporting recommends downloading software only from official channels, indicating concern around malicious or untrusted software distribution. No specific threat actor, industry targeting, or concrete indicators of compromise are provided in the content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Feature-rich remote access trojan offering hidden desktop control, credential theft, fileless attacks, and more, available via subscription.
A modular remote access trojan offered via subscription that supports persistence, data exfiltration, encrypted C2 communications, UAC evasion for privilege escalation, stealthy remote interaction with apps and files, credential/data theft via a stealer module, clipboard management, DNS hijacking, and host-level vulnerability scanning to prioritize exploitation opportunities.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.