Crimson RAT is a Windows-focused, .NET-based remote access trojan used primarily by Transparent Tribe (APT36), a Pakistan-linked cyberespionage group. It has been deployed against Indian government, military, defense, diplomatic, financial, healthcare, education, research, space-technology, and security-adjacent startup targets, as well as organizations connected to Afghanistan. The malware provides remote command execution and surveillance functions, including system and user-information collection, process and drive enumeration, process termination, file and directory operations, file upload and download, screenshot capture, audio recording in some campaigns, and exfiltration to command-and-control infrastructure. Variants support persistence and have ranged from roughly 22 commands to larger command sets. Transparent Tribe commonly delivers Crimson RAT through spearphishing lures, including malicious Office documents, PowerPoint add-ins, archives, and disk-image containers containing deceptive shortcuts and scripts. Campaigns have used decoy documents, macro or OLE-based staging, delayed execution, string obfuscation, security-warning removal, and binary padding to hinder analysis and detection. Later variants added anti-analysis checks, file splitting that can facilitate transfer of large data, and a removable-media worm-loading capability associated with lateral movement.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Кампания против стартапов использовала ISO-образ MeetBisht.iso с LNK-ярлыком, batch-скриптом и Crimson RAT; бинарник Crimson RAT искусственно раздут до 34 МБ мусорными данными.
2024-12-04 ⋅ Microsoft Threat Intelligence Frequent freeloader part I: Secret Blizzard compromising Storm-0156 infrastructure for espionage Crimson RAT MiniPocket TwoDash Wainscot
28 distinct techniques documented for this family, organized by ATT&CK tactic.
Process: List processes Kill process Execute commands
Batch-скрипт снимает Mark of the Web через PowerShell: Remove-Item -Stream Zone.Identifier или Unblock-File.
It also uses Base64 encoding technique to encode the strings... The registry path is encoded in Base64 and while executing it decodes
Transparent Tribe... continuously used Crimson RAT but with either an encoded or a packed version... two new samples that were obfuscated with Eziriz’s .NET Reactor were also found
It then copies and decompresses it into the Documents folder as a screensaver file “hacrvidth vibev.scr” and executes it.
The DLL files dropped are not sideloaded by the AllaKore RAT, and they are legitimate files... These are Microsoft Windows-related libraries...
By using these commands, they can access all the files, pictures, system info, the running processes from the system.
A few of these C2 commands don’t have functionality yet, but they are similar to the ones first documented by Proofpoint.
After collecting the data from the victim’s system, it tries to make a TCP connection to send the data to the C2 server sunnyleone[.]hopto[.]org by using different customized ports each time
Opening the LNK triggers the MSHTA process, which executes a remote HTA file hosted on a compromised domain.
Для Crimson RAT описана C2-связь через собственный TCP-протокол с обфусцированными командами и жёстко прописанными адресами серверов.
135 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
29 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Удалённый троян APT36, доставляемый через LNK/ISO-фишинг. Использует обфусцированный собственный TCP C2, закрепляется в системе и собирает/эксфильтрует данные.
A remote access trojan used by Transparent Tribe to infiltrate victim devices and maintain long-term command-and-control access.
Remote access trojan referenced in Secret Blizzard espionage activity and Snowblind reporting.
Remote access trojan delivered via ISO containers and LNK shortcuts in lure-based campaigns to provide remote control and data theft capability.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.