Sub7, also known as SubSeven and Sub7Server, is a Windows remote access trojan originally released in February 1999 and developed by mobman. It was distributed as a client/server-style RAT, with a GUI client for the operator and a server/payload component for the victim machine. The malware is described as working on Windows 9x and Windows NT systems, with other cited content stating support up to Windows 8.1. Starting with version 2.1, Sub7 could also be controlled via IRC.
The malware provides broad unauthorized remote-control capability. Reported features include keystroke logging, password theft, screenshot capture, webcam and microphone capture, registry editing, chat functions, port scanning, port redirection, ICQ account takeover and chat-history access in version 2.1, and various prank or harassment actions such as swapping mouse buttons, opening and closing the optical drive, changing desktop colors, turning the monitor off or on, and using text-to-speech. The server could notify the operator of victim IP address changes by email, ICQ, or IRC. The server editor allowed customization before delivery, including changing ports and displaying deceptive installation messages. Sub7 did not self-propagate, but it was used to gain unauthorized access and steal sensitive data including passwords and credit card numbers; the worm W32/Leaves used Sub7 as part of its activity in 2001.
Technical analysis in the provided content describes Sub7 payloads as Delphi-compiled PE files. Version 2.0 samples were identified as packed with UPX, while version 2.3 samples were described as packed with ASPack. Command-and-control traffic was reported to be transmitted in plain text without encryption, and the malware’s message handler maps integer-based C2 commands to controller actions. The configuration utility is named EditServer.exe, and server.exe is described as the stub used to build a payload. Version 2.3 is noted as offering Normal and Advanced configuration modes, including downloader support, persistence, plugins, and the ability to append commands for execution during initial deployment.
The content also notes security-relevant implementation details: Sub7 connections could be protected with an operator-chosen password, but reverse engineering reportedly found hardcoded master passwords that allowed access regardless of user-set credentials. Reported examples include predatox for version 1.9, 14438136782715101980 for versions 2.1 through 2.2b, and acidphreak for the DEFCON8 2.1 backdoor. A 2003 Spanish-language phishing email impersonating Symantec was cited as a delivery lure for Sub7.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
Sub7 2.3 provides Normal and Advanced configuration: Normal mode provides most of the commonly used options, while Advanced mode allows the use of a downloader and enables appending commands to the payload for execution during the initial deployment stage.
Software packing is the process of compressing, encrypting, or modifying an executable file to reduce its size and disguise its structure, often used to protect code or evade detection.
Additionally Sub7 has some features deemed of little use in legitimate remote administration like keystroke logging... it can also read keystrokes that were made since the last boot—a capability that can be used to steal passwords, credit card numbers, and other sensitive data.
Additionally Sub7 has some features deemed of little use in legitimate remote administration like keystroke logging... it can also read keystrokes that were made since the last boot—a capability that can be used to steal passwords, credit card numbers, and other sensitive data.
Sub7's server-side (target computer) features include: Recording: ... Screen shots of the computer
The communication channel is not encrypted. Data is transmitted in plain text:
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An early-generation remote access trojan from the 1990s. The article places it among RATs that used direct control architectures and static patching of server stubs to create payloads.
A remote access trojan used here as the example payload for demonstrating manual unpacking of packed malware samples.
A Windows remote access trojan that provides attacker-side control over victim machines, supports payload configuration and persistence, and in later versions could be controlled via IRC. The article discusses controller/payload operation, plaintext C2 communications, and reverse engineering of versions 2.0 and 2.3.
Malware ... Sub7
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.