NineRAT is a DLang-based remote access trojan associated with North Korean activity linked to the Lazarus umbrella, specifically overlaps with Andariel/Onyx Sleet tradecraft, and was reported by Cisco Talos in the Operation Blacksmith campaign. It uses Telegram bots and channels for command-and-control, accepting commands, returning execution output, and transferring files through Telegram APIs including getMe, sendDocument, and getFile, likely to blend malicious traffic with legitimate Telegram activity. Talos reported NineRAT was built around May 2022 and observed in the wild from at least March 2023.
In Operation Blacksmith, the broader intrusion set opportunistically targeted internet-exposed enterprise infrastructure through n-day exploitation, notably CVE-2021-44228 (Log4Shell), including publicly facing VMware Horizon servers. Reported victimology for the campaign included manufacturing, agricultural, and physical security organizations, with specific NineRAT use observed against a South American agricultural organization in March 2023 and a European manufacturing entity around September 2023.
NineRAT consists of a dropper that writes two embedded components to disk and then deletes itself. An instrumentor component named "nsIookup.exe" (using a capital "i" in place of a lowercase "l") executes the payload and supports persistence. Persistence is established via a BAT script that creates a Windows service using sc create, with service names such as "Aarsvc_XXXXXX." Reported operator commands include /info, /setmtoken, /setbtoken, /setinterval, /setsleep, /upgrade, /exit, /uninstall, and /sendfile. Talos also reported NineRAT C2 infrastructure led to discovery of a previously public Telegram bot, "@StudyJ001Bot," referenced in a Korean-language tutorial from 2020.
A 2024 joint FBI-led advisory on DPRK RGB 3rd Bureau activity lists NineRAT among Andariel-developed RATs and implants. That advisory states Andariel commonly gains initial access by exploiting public-facing servers, deploys web shells, establishes persistence via Scheduled Tasks, steals credentials with tools such as Mimikatz, moves laterally with SMB and RDP, and uses custom implants and dual-use tools for command execution, tunneling, and exfiltration. The advisory associates the group with espionage targeting defense, aerospace, nuclear, and engineering organizations, with additional targeting of medical and energy sectors.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Over the last 15 years, the group has developed RATs, including the following... ▪ NineRAT
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
1 distinct technique documented for this family, organized by ATT&CK tactic.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
DLang-based remote access trojan that uses Telegram bots/channels for C2, including command execution, host reconnaissance, and inbound/outbound file transfer; deployed via a dropper + instrumentor chain with Windows service-based persistence.
RAT used for remote access and manipulation of systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.