Vermin is a custom .NET remote access backdoor used in cyber-espionage operations, notably against Ukrainian government institutions. It has been active since at least mid-2016 and has been associated with campaigns that also deployed Quasar RAT and Sobaken RAT, with shared infrastructure observed across those toolsets. Vermin is designed for long-term surveillance and data theft on compromised Windows systems.
The malware supports a broad set of post-compromise capabilities, including process and task enumeration, screen capture, keylogging, clipboard collection, username and local IP address discovery, file deletion, and checks for installed antivirus software through WMI. Optional components extend functionality to audio recording and password theft. Collected data may be written to local files and encrypted with 3DES prior to exfiltration. Vermin also uses protected or obfuscated code and decrypts embedded code, strings, and commands at runtime to hinder analysis.
Observed delivery in espionage campaigns relied on social engineering via malicious email attachments, including disguised archive-style lures and crafted Microsoft Word documents exploiting CVE-2017-0199. Infections were installed by a dropper that placed the payload in the user application-data area and established persistence through a scheduled task executed at regular intervals. The malware family also incorporated anti-analysis and targeting controls, including checks for Russian or Ukrainian keyboard layouts, geofencing logic, sandbox-avoidance heuristics, and refusal to run under usernames associated with automated analysis environments.
Vermin is best characterized as an espionage-oriented RAT/backdoor focused on surveillance, credential collection, and exfiltration from targeted organizations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Among these tricks are using right-to-left override to obscure the attachments’ real extension, email attachments disguised as RAR self-extracting archives, and a combination of a specially crafted Word document carrying a CVE-2017-0199 exploit. | We have detected three different strains of .NET malware in these campaigns: Quasar RAT, Sobaken RAT, and a custom-made RAT called Vermin.
25 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes payloads, strings, configuration files, scripts, URLs, and binaries being obfuscated or encoded using Base64, XOR, RC4, AES, RSA, hex encoding, custom algorithms, and other methods across many malware families and threat actors.
Among these tricks are using right-to-left override to obscure the attachments’ real extension | Among these tricks are using right-to-left override to obscure the attachments’ real extension, email attachments disguised as RAR self-extracting archives
The content repeatedly describes malware and threat actors deleting files, directories, droppers, logs, scripts, temporary files, exfiltrated archives, and uninstalling themselves to cover tracks or reduce forensic artifacts.
The content is a long ATT&CK-style listing of malware and threat groups that 'decrypt', 'decode', 'deobfuscate', 'unpack', or 'decompress' payloads, strings, configuration data, shellcode, and files prior to execution or use.
To make sure that the malware runs on targeted machines only and avoids automated analysis systems and sandboxes, the attackers have deployed several measures.
AdFind can extract subnet information from Active Directory; actors used ipconfig /all, netsh.exe, ifconfig, arp, route, nbtstat, and related APIs/commands to gather IP, MAC, DNS, DHCP, gateway, proxy, routing, ARP, and adapter information.
The content repeatedly describes malware and threat actors collecting the victim username, identifying logged-in users, running whoami, query user, quser, or similar commands to determine the current user or user sessions.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
The content repeatedly describes malware and threat actors collecting host details such as hostname, OS version, architecture, CPU, memory, BIOS, language, and other machine characteristics; e.g., "Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host."
To make sure that the malware runs on targeted machines only and avoids automated analysis systems and sandboxes, the attackers have deployed several measures.
The malware terminates if neither Russian or Ukrainian keyboard layouts are installed, and also if the target system’s IP address is located outside these two countries
The content is a catalog of malware families and threat actors that 'can perform keylogging,' 'log keystrokes,' 'capture keystrokes,' or use 'keylogger' modules/tools.
The content is a MITRE ATT&CK-style listing of malware and threat actors that "can capture screenshots," "take screenshots," "perform screen captures," or "watch the victim's screen." It ends with references to "CopyFromScreen" and "xwd."
Agent Tesla can steal data from the victim’s clipboard. APT38 used a Trojan called KEYLIME to collect data from the clipboard. APT39 has used tools capable of stealing contents of the clipboard.
Agrius used a custom tool, sql.net4.exe, to query SQL databases and then identify and extract personally identifiable information... AppleSeed has automatically collected data from USB drives, keystrokes, and screen images before exfiltration... Ember Bear engages in mass collection from compromised systems during intrusions.
they share parts of their infrastructure and connect to the same C&C servers.
40 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
.NET remote access trojan (RAT) used for espionage, providing persistent access to targeted systems, primarily used against Ukrainian government institutions.
Remote access trojan that gathers the username from the victim machine.
Gathers local IP addresses from victim systems.
Remote access trojan that decrypts code, strings, and commands on victim systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.