Sakura RAT is a GitHub-hosted trojanized malware project presented as a remote access trojan, but Sophos X-Ops found it was likely nonfunctional as an actual RAT: many forms were empty and portions of the code appeared copied from AsyncRAT. Instead, the repository contained a malicious Visual Studio project PreBuild event that silently downloaded malware when the project was compiled, making the primary victims the users attempting to build or run it. Reported targets were mainly inexperienced threat actors, gamers seeking cheats, and other users downloading offensive tooling from GitHub, rather than enterprise victims.
Sophos linked Sakura RAT to a broader GitHub malware distribution campaign associated with the identifier and email address ischhfd83@rambler.ru. In that cluster, researchers identified 141 related repositories, 133 of which were backdoored. Most masqueraded as gaming cheats, malware projects, exploits, attack tools, bots, or cryptocurrency utilities. Delivery mechanisms observed across the cluster included Visual Studio PreBuild backdoors, Python backdoors, JavaScript backdoors, and .scr files disguised as .sln files using right-to-left override characters. The operators also used GitHub Actions workflows named "Star" and large volumes of automated commits to make repositories appear actively maintained and legitimate.
The Sakura RAT / related infection chain wrote a VBS script to the victim Temp directory, which then wrote and executed PowerShell. That stage decoded obfuscated URLs from services including rlim.com, glitch.me, Pastebin, Pastejustit, and paste.fo, and ultimately downloaded a password-protected archive, SearchFilter.7z, from a GitHub releases page associated with unheard44/fluid_bean. The archive contained an Electron-based payload whose app.asar included heavily obfuscated code for Telegram communications, host reconnaissance, screenshot capture, scheduled task creation, registry manipulation, Windows Defender exclusion or disabling actions, shadow copy deletion, and infection notification to the attacker. Prior technical analysis cited by Sophos indicated downstream payloads included AsyncRAT modules, Remcos, and Lumma Stealer.
Additional high-confidence indicators and recurring artifacts mentioned in the reporting include the email address ischhfd83@rambler.ru, the hardcoded Fernet key "vibe.process-byunknown" used in Python and JavaScript variants, the Pastebin user Ali888Z, recurring identifiers such as "Unknown," "unkownx," and "Muck," Telegram bot infrastructure, and GitHub-hosted SearchFilter.7z. Sophos assessed the activity overlaps with or resembles a broader distribution-as-a-service ecosystem, with possible links noted to campaigns discussed under names such as Stargazer Goblin, GitVenom, and Water Curse, though attribution remained inconclusive.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Cyber researchers have been tracking the cluster since March 2023, noting the use of at least 76 GitHub accounts using Visual Studio files to conceal payloads like SMTP email bombers and a remote access trojan called Sakura-RAT.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
Sophos thinks a single person or group called "ischhfd83" is behind more than a hundred backdoored malware variants... Researchers linked the hundreds of GitHub repositories to a single Russian email address... Sophos researchers looked into ischhfd83's other repositories, finding 141, 133 of which were backdoored in some way or another.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
Other indicator types observed in public reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An open-source RAT project on GitHub that was itself non-functional/incomplete, but was trojanized with malicious build-time backdoors intended to infect people who compiled it.
An open-source RAT project on GitHub that was non-functional as malware itself in the analyzed sample, but was backdoored to infect users who compiled it.
Remote access trojan distributed via weaponized GitHub repositories; used to enable data exfiltration (credentials, browser data, session tokens) and establish long-term access on compromised systems.
A remote access trojan whose trojanized GitHub repository was backdoored to infect users compiling it, leading to delivery of information stealers and other RATs.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.