LimeRAT is a Windows remote access trojan written in Visual Basic .NET and commonly characterized as a modified variant of njRAT. It supports encrypted client-server communications, plugin-based extensions, remote desktop control, file management, payload downloading, keylogging, credential theft, host reconnaissance, and persistence. Publicly available LimeRAT builds have also advertised ransomware, cryptocurrency theft, cryptocurrency mining, DDoS, USB propagation, anti-virtual-machine checks, and remote-desktop enablement capabilities.
LimeRAT has been delivered through multi-stage phishing and spearphishing campaigns, including malicious Office documents with VBA macros, archive files, ISO images, Visual Basic Script, and PowerShell loaders. Observed delivery chains commonly use script obfuscation, legitimate web services for staging, in-memory .NET loading, and injection into trusted Windows processes. Campaigns targeting Colombian users have used Spanish-language judicial and banking lures; activity has also targeted government organizations in Afghanistan, India, Italy, Poland, and the United States. LimeRAT has been used by or alongside the Latin America-focused Blind Eagle, also tracked as TAG-144 and APT-C-36, as well as in broader commodity-RAT distribution operations. It primarily targets Windows systems with compatible .NET Framework installations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Furthermore, the RAT used in this scenario was Lime-RAT, a modified version of njRAT.
In some cases, the final stage PowerShell script contained up to seven various RATs. These are typically NjRat, BitRat, Nanocore RAT, QuasarRat, LimeRat, and Warzone.
36 distinct techniques documented for this family, organized by ATT&CK tactic.
The next PowerShell script attempts to achieve persistence by creating a new Scheduled Task called "Office" that is executed immediately and then repeated every two minutes
The .rar file contains a Visual Basic Script ... to download and execute a new Powershell script
will create a Windows Script Host Shell Object to download and execute a new Powershell script by executing the following command
The next PowerShell script attempts to achieve persistence by creating a new Scheduled Task called "Office" that is executed immediately and then repeated every two minutes
The next PowerShell script attempts to achieve persistence by creating a new Scheduled Task called "Office" that is executed immediately and then repeated every two minutes
The intrusion set embedded Unicode icons into Base64-encoded PowerShell strings, replaced those icons with ASCII characters at runtime, and used reversed Base64-encoded URLs and payloads.
T1036 Masquerading The registered task/service pretends to be benign by name
loading them using a puppet process injection within the memory of process “C:\Windows\Microsoft.NET\Framework\v4.0.30319\cvtres.exe” ... or in “C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe”
This is accomplished by invoking aspnet_compiler.exe, injecting the final payload, and executing it.
"The YIPPHB dropper is executed using the Installutil.exe command-line utility to start the RAT phase."
T1071 Application Layer Protocol HTTP/DNS requests are used in the C&C traffic
The loader and subsequent stages use WebClient and HTTPS/HTTP URLs to retrieve encoded payloads; the RAT connects to a configured command-and-control server.
The loader is downloaded from a TinyURL-resolved Discord CDN location; the loader subsequently downloads the YIPPHB dropper and the RAT implant from remote URLs.
Remote Administration Tool For Windows ... Auto Task Force enable Windows RDP ... File manager ... Remote desktop ... Downloader Keylogger
167 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Commodity remote access trojan referenced as one of the RAT families used in Blind Eagle campaigns.
TAG-144’s Persistent Grip on South American Organizations AsyncRAT BitRAT DCRat LimeRAT NjRAT PureCrypter Quasar RAT Remcos
Remote access trojan used as a fallback payload when compatible .NET versions for AsyncRAT are not found. It communicates with the same C2 infrastructure, supports plugin-based extension, and is described as capable of screenshots, keylogging, credential/confidential data theft, botnet enrollment, network discovery, and lateral movement.
Commodity remote access trojan used by TAG-144 for remote access to victim environments.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.