msoRAT is a Windows remote access trojan used in financially motivated intrusions associated with the CryptoMimic/CryptoCore activity cluster and reported as part of tooling linked by multiple researchers to Lazarus-aligned operations, including TA444/APT38/Bluenoroff overlap. It has been observed as a later-stage payload downloaded and executed by the VBScript-based Cabbage RAT-C during targeted attacks against financial organizations, especially cryptocurrency exchanges and related businesses.
The malware is a packed DLL executed through rundll32 and uses obfuscated arguments protected with Base64 and RC4. It communicates with command-and-control infrastructure over encrypted channels and reads from and writes to data associated with msomain.sdb, a trait that has been highlighted as distinctive across related samples. Reported functionality includes remote command execution, host reconnaissance, process management, file upload and download, file deletion, compression, registry modification, and payload execution. Analyses also describe PE injection into explorer.exe and injection activity involving lsass.exe, along with API-call obfuscation intended to hinder reverse engineering.
msoRAT appears in post-compromise phases rather than as an initial delivery implant. In observed intrusions, operators first gained access through spearphishing or LinkedIn lures leading to malicious shortcut-based and script-based staging, then deployed Cabbage RAT components, browser credential theft tooling, msoRAT, and additional credential-stealing malware. The broader campaigns emphasized theft from cryptocurrency organizations and other financial targets, with operators conducting interactive post-exploitation, credential access, and cleanup. msoRAT has also been described in some reporting as part of a post-exploitation backdoor set used by TA444 in cryptocurrency-focused operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
msoRAT was downloaded and executed... DLL file that has RAT function... Can perform tasks in accordance with the order received from C&C server.
msoRAT was downloaded and executed... DLL file that has RAT function... Can perform tasks in accordance with the order received from C&C server.
Their collection of post-exploitation backdoors has included the msoRAT credential stealer, the SWIFT money laundering framework DYEPACK, and various passive backdoors and virtual "listeners" for receiving and processing data from target machines.
Their collection of post-exploitation backdoors has included the msoRAT credential stealer, the SWIFT money laundering framework DYEPACK, and various passive backdoors and virtual "listeners" for receiving and processing data from target machines.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
The group executed windows commands using Cabbage RAT-C.
msoRAT injects a DLL file by adding the registry key ‘Security Packages’... msoRAT injected something into lsass.exe process.
browser info stealer itself and its output were deleted after execution... lsass.exe deleted credential stealer.
Change date of creation, last access and last update for designated file.
Execute a command after assigning SeDebugPrivilege privilege to designated user.
The attacker stole information on the victim host or investigated other hosts on the same network by leveraging these commands... netstat.exe, ping.exe, net.exe view.
Cabbage RAT-B collects and sends the system and task information of its working environment to the C&C server.
Send HTTP request to C&C server, and execute the code included in response data
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A post-exploitation credential-stealing RAT/backdoor used by TA444.
Post-exploitation remote access/backdoor tool used by TA444.
A packed DLL-based RAT executed via rundll32 that communicates over HTTPS, supports host reconnaissance, file upload/download, command execution, privilege-related actions, and code/PE injection. It also downloads and persists a credential stealer and injects into lsass.exe.
A packed DLL-based RAT used in the later stage of the CryptoMimic intrusion. It uses obfuscated arguments and WINAPI resolution, communicates with a C2 server, accesses %WINDIR%\apppatch\msomain.sdb, can execute commands with SeDebugPrivilege, manipulate files, inject a PE into explorer.exe, and launch the Browser Info Stealer.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.