Crimson RAT is a custom .NET remote access trojan widely associated with APT36, also known as Transparent Tribe, a Pakistan-linked espionage actor. Public reporting ties it to long-running cyber espionage operations primarily targeting Indian government, military, diplomatic, education, academic, and strategic sectors, with later reporting also describing targeting of Indian startups, especially cybersecurity- and intelligence-related organizations, and some activity focused on Afghanistan.
Observed infection vectors include spearphishing emails delivering malicious Microsoft Office documents with VBA macros, OLE-embedded lures, ZIP archives, ISO container files, and malicious LNK shortcuts. Macro-based delivery has reconstructed ZIP payloads from obfuscated data stored in Office forms, written archives under %ALLUSERPROFILE% or C:\ProgramData, extracted embedded executables, and launched Crimson RAT. Other campaigns used ISO files containing an LNK masquerading as an Excel document, a decoy document, batch scripts, and a Crimson RAT payload disguised as an executable such as "Excel" or "MicrosoftUpdate.exe". Reporting also notes use of malicious documents themed around Indian government, education, assignments, and current events.
Crimson RAT provides typical espionage-focused RAT functionality. Across the cited reporting, capabilities include remote command execution, process listing and termination, file system browsing, file upload/download/deletion, recursive file search and exfiltration, screenshot capture, live screen streaming, system reconnaissance, and collection of victim metadata such as hostname, username, OS version, IP, NIC, client ID, and installation path. Additional reporting attributes broader Crimson tooling with microphone audio surveillance, webcam capture, keystroke logging, browser password theft, removable-media theft, and deployment of secondary payloads. One analyzed variant using namespace dhrwarhsav supports remote command execution, process management, file exfiltration, screenshot capture, live screen streaming, persistence via HKCU\Software\Microsoft\Windows\CurrentVersion\Run, and downloading/executing additional payloads such as dorbanvca.exe.
Multiple reports describe Crimson RAT evolution over time. Version 1.0.0.0 samples compiled in 2019, 2021, and 2023 supported file download, deletion, process termination, screen capture, and process enumeration/exfiltration, while using simple command obfuscation. A more advanced v2.1.0.0 variant referred to as Kosovo added broader functionality and evasion, including a command to load usbworm malware for removable-media propagation, file-splitting that may aid exfiltration of large files, repeated process checks, ComputeStringHash-based string hiding, and anti-analysis checks using Win32_BaseBoard.SerialNumber and CPU ID queries. SentinelLABS also observed 2022 Crimson RAT variants supporting either 40 or 65 commands, anti-analysis delays of 61, 180, or 241 seconds, machine-name checks against G551JW and DESKTOP-B83U7C5 before creating Run-key persistence, and obfuscation including malformed function names, dynamic string resolution, and Eazfuscator.
Known command-and-control indicators mentioned in the content include richa-sharma.ddns[.]net, used by multiple 2022 variants and by the Kosovo sample on port 10101; 107.175.64.209 with ports 6728, 8661, 10614, 14822, and 18443 for the dhrwarhsav variant; 93.127.133.58:1097 in a 2025 campaign; and additional sample-specific indicators 101[.]155.260.18:6828, 10[.]105.106.118:6188, and 101[.]125.206.108:6859. Non-standard ports 18661, 20856, 26868, 29261, and 36628 were also reported in startup-targeting activity. Reported file and registry artifacts include dhrwarhsav.exe, dorbanvca.exe, and HKCU\Software\Microsoft\Windows\CurrentVersion\Run_dreb. Sample hashes explicitly listed in the content include MD5 8a1f4a512fe9edbcc62ba4b1c3e08f0a, 77c29d464efcae961424ae050453ef11, fed22809d70062733cd1c34e16b75c05, and e40e0a71efd051374be1663e08f0dbd8, as well as SHA-256 ecd7d7a27a2a043919a233bb91e3b009c05b7c81ff132a7c29228e1c45d2b6a6, f5e7b8dddd4137ac008186a4c5e9cb644dc1bbddb61612c29c2087b1efe48974, 63f96f77786b8499ce4e08a1883a1d5569563da14b507390cfcbd7b37c5dfb9a, and 947e75dc1f9b8a6d74a6d55afa7513ed86db907965cf0935ebb26c17f0ec6c5d.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The Evolution of APT36’s Crimson RAT: Tracking Variants and Feature Expansion Over the Years
2024-12-04 ⋅ Microsoft Threat Intelligence Frequent freeloader part I: Secret Blizzard compromising Storm-0156 infrastructure for espionage Crimson RAT MiniPocket TwoDash Wainscot
28 distinct techniques documented for this family, organized by ATT&CK tactic.
It’s a surprise that the Crimson RAT variant embedded a command for loading the malware usbworm. Which means it can do lateral movment through removable media like usb .
Based on known behavior of this group, we suspect that the documents have been distributed to targets as attachments to phishing emails.
“execute arbitrary commands… execute commands with COMSPEC and receive the output… This tab allows the attacker to execute arbitrary commands on the remote machine.”
At version 2.1.0.0, the Crimson RAT uses ComputeStringHash to do evasion; it is a compiler-generated method that calculates a hash of a string, which can hide string comparisons and avoid static string detection.
Most of the Crimson RAT variants we analyzed evaluate whether they execute at a machine named G551JW or DESKTOP-B83U7C5 and establish persistence by creating a registry key under \SOFTWARE\Microsoft\Windows\CurrentVersion\Run only if the victim’s machine name differs.
Most of the Crimson RAT variants we analyzed evaluate whether they execute at a machine named G551JW or DESKTOP-B83U7C5 and establish persistence by creating a registry key under \SOFTWARE\Microsoft\Windows\CurrentVersion\Run only if the victim’s machine name differs.
the command's response from the server only used simple string prefix “rlbwrarhsa-“ concatenation, string insertion, and changes to the logic conditions to do obfuscation for evasion... using different characters, like “| or !,” to split strings to handle obfuscation.
This lures users to double-click the graphic to view the content, which activates an OLE package that stores and executes Crimson RAT masquerading as an update process (MicrosoftUpdate.exe).
The basic functionalities are designed as remote access trojans: ... enumerate and exfiltrate processes information
Features of Crimson RAT include exfiltrating system information, capturing screenshots, starting and stopping processes, and enumerating files and drives.
Features of Crimson RAT include exfiltrating system information, capturing screenshots, starting and stopping processes, and enumerating files and drives.
Another evasion technique for anti-VM/anti-analysis with querying hardware serials like Win32_BaseBoard.SerialNumber or querying CPU id information.
Features of Crimson RAT include exfiltrating system information, capturing screenshots, starting and stopping processes, and enumerating files and drives.
The basic functionalities are designed as remote access trojans: upload GIF, download file, delete a file, kill a process, capture screen...
“perform audio surveillance using microphones… The malware uses the NAudio library to interact with the microphone… pushed to the victim’s machine using a special command.”
the ddns[.]net is a Dynamic DNS domain, commonly used by attackers for Command & Control (C2) servers
“Crimson RAT connects to its hardcoded C2 server… 93.127.133.58 (port 1097)… direct TCP C2 on rotating ports.”
52 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote access trojan referenced in Secret Blizzard espionage activity and Snowblind reporting.
Remote access trojan delivered via ISO containers and LNK shortcuts in lure-based campaigns to provide remote control and data theft capability.
Remote access trojan used by Transparent Tribe/APT36 to compromise targets via ISO-delivered payloads; provides remote surveillance and control capabilities including screen monitoring, audio recording, file theft, and system control. Uses evasion such as file-size bloating with junk data and randomized function names; communicates to C2 over a custom TCP protocol on non-standard ports.
Remote access trojan used for surveillance, data exfiltration, and host reconnaissance; delivered via spear-phishing ISO containing a malicious LNK and staged payloads.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.