BitRAT is a commodity Windows remote-access trojan sold on underground criminal forums since 2020. It provides operators with remote control and system, process, service, file, and application management functions. Documented capabilities include credential theft, browser-data theft, keylogging, clipboard monitoring, screen and webcam access, microphone recording, data exfiltration, file transfer, hidden-VNC and remote-desktop access, SOCKS proxying, UAC bypass, Windows Defender evasion, DDoS functionality, and XMRig-based cryptocurrency mining. BitRAT variants have incorporated TinyNuke-derived hidden-desktop functionality.
BitRAT has been delivered through phishing and malspam, malicious Office documents and attachments, password-protected archives, trojanized Windows activation tools and other cracked software, fake browser updates, watering-hole activity, and NFT-themed lures. Loaders and crypters have also deployed it through in-memory execution and process injection. Persistence mechanisms observed in BitRAT delivery chains include Startup-folder execution, scheduled tasks, and registry-based startup configuration.
The malware has been used by multiple criminal operations, including campaigns attributed to APT-C-36 (Blind Eagle) targeting organizations in Colombia and elsewhere in South America. Observed victim sectors include government, finance, healthcare, telecommunications, energy, oil and gas, as well as German automotive organizations and users seeking pirated software.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“After deobfuscating the executable file within the password-protected archive, we are presented with a RAT called BitRAT.”
In some cases, the final stage PowerShell script contained up to seven various RATs. These are typically NjRat, BitRat, Nanocore RAT, QuasarRat, LimeRat, and Warzone.
all of them have been associated with off-the-shelf malware like QuasarRAT, BitRat, and similar.
36 distinct techniques documented for this family, organized by ATT&CK tactic.
...it can be employed in various operations, such as trojanized software, phishing and watering hole attacks.
...it can be employed in various operations, such as trojanized software, phishing and watering hole attacks.
it decodes a command string and executes it using a WMI (Windows Management Instrumentation) object.
It then runs schtasks to create a schedule task named “calendersw” in the system “Task Scheduler“... It is also a persistence mechanism. Once it starts, back.htm adds more scheduled tasks.
2022-01-23 ⋅ forensicitguy ⋅ Tony Lambert HCrypt Injecting BitRAT using PowerShell, HTAs, and .NET
2022-01-23 ⋅ forensicitguy ⋅ Tony Lambert HCrypt Injecting BitRAT using PowerShell, HTAs, and .NET
The .inf file contains a hex encoded second stage dll payload which is decoded via certutil, written to %temp%\ and executed by rundll32.
It contains an auto-start Macro that starts using a VBA (Visual Basic Application) method called “Auto_Open()” when the Excel file is opened.
The HTML file contains a piece of JavaScript code... It creates an object, “Wscript.Shell”... In Figure 3.1 we can see it runs five command-line applications.
It then runs schtasks to create a schedule task named “calendersw” in the system “Task Scheduler“... It is also a persistence mechanism. Once it starts, back.htm adds more scheduled tasks.
The final stage PowerShell is responsible for deobfuscating and injecting the payload (RATs) into the given process.
It then performs process hollowing to inject the malware payload into a newly-created process of “aspnet_compiler.exe”.
The downloaded file is a password-protected archive, the password for which is mentioned in the email, the email attachment, or both.
The criminals behind the campaign reportedly distribute the payloads in the guise of Windows 10 Pro license activators... The malicious file, named W10DigitalActiviation.exe, mimics a simple, one-button unofficial Windows 10 activator.
The final stage PowerShell is responsible for deobfuscating and injecting the payload (RATs) into the given process.
It then performs process hollowing to inject the malware payload into a newly-created process of “aspnet_compiler.exe”.
After the downloader performs the operations above, it deletes itself from the infected computer in an attempt to wipe its tracks.
At the end of each malware code segment, the code calls the “Load()” method to load the inner .Net module... then calls the Invoke() method to invoke the “projFUD.PA.Execute()” function... with two parameters, which are an exe file’s full path and a fileless malware payload.
The malicious tool can perform a wide range of operations, including ... generic keylogging.
The malicious tool can perform a wide range of operations, including ... clipboard monitoring ...
I used the REST API to manage comments on issues and pull requests... built a GitHub-specific URL to post a comment on an issue, added a Bearer token header... | As you can see, any API service can be used as a C2 and Github is not the exception.
The configuration is decrypted to the following string, as shown in Figure 11, including a command-and-control (C&C) server and a port.
267 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
35 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote-access trojan delivered through APT-C-36 spear-phishing emails. The payload is distributed in password-protected archives reached through geographically filtered URL shorteners. Its configuration, including C2 server and port, is Camellia-encrypted; the campaign uses location and VPN filtering to evade analysis and target selected victims.
Named RAT variant in the AsyncRAT/DCRAT family lineage.
A low-volume DCRAT fork with minimal confirmed live infrastructure.
A low-cost commodity remote access trojan sold on underground forums and used via trojanized software, phishing, and watering hole attacks. It supports data exfiltration, UAC bypass, DDoS, clipboard monitoring, webcam access, credential theft, audio recording, XMRig coin mining, and keylogging.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.