Houdini, also known as WSHRAT, is a long-running Windows remote access trojan first observed in 2013 and commonly implemented in Visual Basic Script, with additional JavaScript-based loader variants used in some campaigns. It provides typical RAT functionality and has been associated with malicious script delivery chains that execute obfuscated code, decode embedded second stages, and launch additional components. Technical analysis of JScript samples shows multi-stage deobfuscation using placeholder substitution, base64-decoded payloads, and runtime execution through eval, with some capabilities implemented by decoding and running embedded .NET executables rather than by script logic alone.
Observed functionality includes remote access, keylogging, reverse proxy capability, and broader post-compromise control of infected hosts. Analyses also reference defense-evasion behavior and UAC-bypass-related tradecraft. WSHRAT has been distributed by script-based loaders such as RATDispenser, which commonly arrives as a malicious JavaScript attachment in email lures, writes a VBScript stage, and then drops or downloads the final payload. It has also appeared in broader malware delivery ecosystems using compressed archives, malicious scripts, and collaboration-platform-hosted payload retrieval.
The malware targets Windows systems and has been linked to commodity cybercrime activity rather than a single exclusive operator. It has been observed in campaigns delivering multiple RAT and stealer families, and reporting has also associated WSHRAT-linked samples with operations attributed to Black Basta, where malicious VBS, MSI, LNK, JS, and HTA delivery mechanisms were discussed alongside credential abuse and follow-on intrusion activity. Houdini remains notable for heavy obfuscation, script-based staging, and flexible payload execution that support persistence, surveillance, and remote control on compromised Windows hosts.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
Nowadays it is really a common thing for a malware to have a crypter packer, obfuscation and encryption to hide its code from analyst, evade AV detections , bypassed emulation and so on.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote access trojan referenced in the sample list, associated in this content with JavaScript delivery.
A VBS RAT, also known as Houdini, with typical remote access trojan capabilities; one of the most frequently delivered payloads of RATDispenser.
A JavaScript-based remote access trojan analyzed as a multi-stage obfuscated loader. It uses string replacement, Base64 decoding, and hex-encoded string arrays to hide functionality, and contains features such as RDP, keylogging, and reverse proxy by decoding and executing embedded .NET payloads. The content also mentions UAC bypass and defense evasion techniques.
Remote access trojan delivered via collaboration platforms (e.g., Discord).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.