Cardinal RAT is a low-volume Windows remote access trojan associated with targeted intrusions against financial technology organizations, particularly Israel-based companies involved in forex and cryptocurrency trading. It has been observed since at least 2015 and is notable for being delivered through malicious Microsoft Excel documents whose macros invoke a downloader commonly referred to as Carp. That downloader decodes embedded C# source code, writes it to disk, compiles it locally with the native Windows C# compiler, and then retrieves and decrypts the next-stage payload, making Cardinal RAT a documented example of compile-after-delivery tradecraft.
Once installed, Cardinal RAT establishes persistence through a Windows user-logon autostart registry value and uses a watchdog component to maintain both the persistence setting and the malware process. The malware has also been observed using process injection into newly spawned legitimate Windows .NET-related executables to blend execution with normal system activity. Its code and artifacts are obfuscated and encrypted, including AES-protected downloaded stages, decoded resources, and custom-encrypted command-and-control traffic using XOR and addition operations, with compressed communications in some variants. Later versions also introduced stronger obfuscation, including steganographic extraction of a payload from an embedded bitmap and widespread renaming of functions and variables.
Cardinal RAT supports a broad remote administration and surveillance feature set. Confirmed capabilities include collecting host and user information, executing commands, downloading and executing additional payloads, reverse proxying, password recovery, keylogging, screenshot capture, self-update, self-uninstall, and browser cookie cleaning. It can communicate over multiple command-and-control host and port combinations, indicating built-in communication resilience. Reporting has also noted overlap in victimology and timing with EVILNUM activity, suggesting a possible operational relationship, though a common operator has not been confirmed.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
29 distinct techniques documented for this family, organized by ATT&CK tactic.
The malware itself is equipped with a number of features, including... Execute command
The LNK file executes the following command: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe -windowstyle hidden "%APPDATA%\Microsoft\Windows\IEConfig\[random]\sqlreader.exe"
The content repeatedly describes threat actors and malware using cmd.exe, the Windows command shell, to execute commands, launch payloads, run batch files, and automate actions on compromised hosts.
attempted to lure victims into enabling malicious macros within email attachments... prompted victims to accept macros... Word documents containing malicious macros.
ADVSTORESHELL is capable of setting and deleting Registry values. Agent Tesla can achieve persistence by modifying Registry key entries. APT41 used a malware variant called GOODLUCK to modify the registry in order to steal credentials.
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
The remaining segment of the embedded resource is decrypted using a 16-byte XOR key, resulting in a .NET executable. This executable is injected into one of the following two legitimate executables or processes on the system.
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
Unlike previously discussed samples, this latest instance of Cardinal RAT employs various obfuscation techniques to hinder analysis of the underlying code... all of the functions, methods, and variables have been renamed to MD5 hashes.
The first layer of obfuscation comes in the form of steganography; the initial sample is compiled with .NET and contains an embedded bitmap (BMP) file. Upon execution, the malware will read this file, parse out pixel data from the image, and decrypt the result using a single-byte XOR key.
Adversaries may attempt to make payloads difficult to discover and analyze by delivering files to victims as uncompiled code. Text-based source code files may subvert analysis and scrutiny from protections targeting executables/binaries. These payloads will need to be compiled before execution; typically via native utilities such as ilasm.exe, csc.exe, or GCC/MinGW.
The remaining segment of the embedded resource is decrypted using a 16-byte XOR key, resulting in a .NET executable. This executable is injected into one of the following two legitimate executables or processes on the system.
The content repeatedly describes malware and threat actors deleting files, directories, droppers, logs, scripts, temporary files, exfiltrated archives, and uninstalling themselves to cover tracks or reduce forensic artifacts.
The content repeatedly describes malware and threat actors collecting the username, identifying the current user, enumerating logged-on users, or running commands such as whoami, query user, and quser to determine user context on compromised systems.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
The content repeatedly describes malware and threat actors collecting host details such as hostname, OS version, architecture, CPU, memory, BIOS, language, and other machine characteristics; e.g., "Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host."
Many entries describe XOR, XOR/ADD, bitwise NOT and XOR, ROR plus XOR, hexadecimal encoding after encryption, and custom encoding/obfuscation of HTTP traffic or beacons.
APT41 used the Steam community page as a fallback mechanism for C2. Bazar has the ability to use an alternative C2 server if the primary server fails. BISCUIT malware contains a secondary fallback command and control server that is contacted after the primary command and control server.
After the configuration is parsed, Cardinal RAT will proceed with making attempts at connecting with the C2.
The malware itself is equipped with a number of features, including... Act as a reverse proxy
125 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
57 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote access trojan that injects into newly spawned native Windows processes.
Remote access trojan that collects the username from a victim machine.
Remote access trojan that persists by setting the Windows Load registry key to its executable.
Remote access trojan that encrypts C2 traffic using a secret key with XOR and addition operations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.