Houdini RAT is a VBS-based remote access trojan used by the WIRTE threat actor in campaigns targeting Middle Eastern diplomatic and governmental entities. The malware is typically delivered via decoy documents in Arabic, themed around sensitive political or religious topics, and distributed as VBS files that open the decoy and execute the backdoor. Houdini RAT achieves persistence by copying itself to the APPDATA directory (as Update.vbs) and may use PowerShell for further payload execution, sometimes leveraging the Empire post-exploitation framework. Communication with C2 infrastructure occurs over unencrypted HTTP, with known C2 servers including 149.28.14[.]103:535 and domains such as micorsoft[.]store and office365-update[.]co. The malware's infection vector is unsophisticated but effective, with low initial detection rates by antivirus solutions. It is used to target diplomats, defense professionals, and law enforcement in Palestine, Saudi Arabia, Kuwait, and Gaza. Technical consistencies include base64-encoded decoy documents, typographical errors in function names, and the use of regsvr32.exe to execute PowerShell via SCT files. The infrastructure supporting Houdini RAT has shifted over time, including the use of Cloudflare for obfuscation and changes in C2 IP addresses.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
The payload is a VBS file, which, in some cases, comes obfuscated or encoded with couple of layers.
The second stage is basically FILE_DATA which is injected to ‘msbuild.exe’ using LOADER_DATA (RunPE).
14 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.