SQLRat is a Windows malware family associated with FIN7. It has been used in intrusion chains that rely on user interaction, including lures that trick victims into clicking embedded image content to trigger script execution. The malware uses PowerShell extensively as part of its execution flow and has been observed creating a Meterpreter session, indicating use as a post-compromise access and control component rather than a simple standalone payload.
SQLRat employs layered scripting and obfuscation, including scripts that deobfuscate additional scripts during execution. It has also been observed deleting scripts after use, consistent with defense-evasion and anti-forensics tradecraft. For persistence, SQLRat creates scheduled tasks in user-accessible Windows locations. These behaviors align with FIN7’s broader operational patterns of phishing-led intrusion, script-heavy execution chains, and stealthy post-exploitation activity against enterprise victims.
The malware is primarily linked to financially motivated operations attributed to FIN7, a group known for targeting sectors such as retail, hospitality, and restaurants, while also expanding into other industries. Based on the observed behaviors, SQLRat functions as a remote-access-oriented implant or backdoor used after initial compromise to execute follow-on actions and maintain footholds on Windows systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
Empire has modules for executing scripts. EvilBunny has an integrated scripting engine to download and execute Lua scripts. SQLRat has used SQL to execute JavaScript and VB scripts on the host system.
The content repeatedly describes threat actors and malware using PowerShell to execute payloads, run commands, download additional malware, perform lateral movement, evade defenses, and execute scripts in memory. | Examples include: 'APT28 downloads and executes PowerShell scripts and performs PowerShell commands'; 'APT3 has used PowerShell on victim systems to download and run payloads after exploitation'; 'TA505 has used PowerShell to download and execute malware and reconnaissance scripts.'
The content notes use of macros in Word/Office documents and VB scripts, including examples such as APT28, Dark Caracal, menuPass, TrickBot, OceanSalt, OilRig, Nomadic Octopus, and SQLRat executing VB scripts on hosts.
Examples include Cobalt Group using a JavaScript backdoor to launch cmd.exe, NanoCore using JavaScript files, Orz executing commands with JavaScript, Patchwork using JavaScript code, and SQLRat executing JavaScript on the host system.
has attempted to get victims to launch malicious Microsoft Word attachments delivered via spearphishing emails... has required user execution of a malicious MSI installer... has been executed through user installation of an executable disguised as a flash installer.
lured victims to double-click on images in the attachments they sent which would then execute the hidden LNK file.
Sandworm Team leveraged Microsoft Office attachments which contained malicious macros that were automatically executed once the user permitted them... APT29 has used various forms of spearphishing attempting to get a user to open attachments... DarkGate is distributed through phishing links to VBS or MSI objects requiring user interaction for execution.
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
"Action RAT's commands, strings, and domains can be Base64 encoded within the payload." / "ADVSTORESHELL... strings... encrypted with an XOR-based algorithm; some strings are also encrypted with 3DES and reversed." / "APT29 has used encoded PowerShell commands." / "APT41 used VMProtected binaries..."
25 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
RAT that uses PowerShell to create Meterpreter sessions.
Remote access trojan with scripts that deobfuscate additional scripts.
Remote access trojan relying on user clicks on an embedded image to execute scripts.
Remote access trojan that deletes scripts after use.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.