BitRAT is a Windows remote access trojan (RAT) and a descendant of the AsyncRAT malware family. Censys mapped its lineage as AsyncRAT → DCRAT (DarkCrystal RAT) → BitRAT, alongside related forks such as VenomRAT, EchoRAT, Gh0stRAT, CyberSpike, Dumpling RAT, and DarkRAT. The malware appears in reporting as a commodity/open-source or cracked RAT used in multi-stage intrusion chains and malware delivery ecosystems.
BitRAT has been observed or referenced in campaigns involving multiple threat actors and delivery chains. Reporting cited it among the RATs used by TAG-144 / Blind Eagle, which has targeted Colombian government entities and other organizations in South America via spearphishing and staged payload delivery. Kaspersky also reported BlindEagle rotating among open-source RATs including BitRAT. BitRAT was additionally reported as a companion payload in campaigns delivering Rhadamanthys, and historical reporting on the Blister loader noted a campaign that reportedly dropped Cobalt Strike and BitRAT. Check Point also listed BitRAT among malware families delivered by the dotRunpeX injector.
Infrastructure and detection reporting directly tie BitRAT to command-and-control activity. As of 16 June 2026, Censys had confirmed one BitRAT command-and-control host, tracked as THREAT-0162. Censys assessed inherited DCRAT TLS certificate metadata as the most reliable detection signal across the broader AsyncRAT family, including BitRAT. The reported family-wide indicator is self-signed TLS certificates on non-standard ports with subject/issuer patterns such as "O=<Name> By <author>, L=SH, C=CN," with variant names and builder handles appearing in certificate fields. A Nuclei template exists for BitRAT C2 detection at ssl/c2/bitrat-c2.yaml, and public references also point to Censys hunting queries for BitRAT infrastructure.
BitRAT is also referenced in underground-market advertising as an "advanced Windows RAT," further supporting its role as a commodity Windows remote administration malware family. High-confidence content does not provide additional verified technical details here on its internal modules, persistence, or specific data-theft functions beyond its classification and observed use as a RAT.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
TAG-144 leverages a range of commodity remote access trojans (RATs), including AsyncRAT, REMCOS RAT, DcRAT, njRAT, LimeRAT, QuasarRAT, BitRAT, and a Quasar variant known as BlotchyQuasar.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
12 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named RAT variant in the AsyncRAT/DCRAT family lineage.
Windows remote access trojan promoted as an advanced, fully activated RAT.
BitRAT is a remote access trojan (RAT) that provides attackers with persistent remote control over infected systems, often used for data theft, surveillance, and further malware deployment.
Observed as a companion payload delivered alongside Rhadamanthys.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.