LilimRAT is a customized Windows remote access trojan derived from the open-source Lilith RAT and associated with MirrorFace, a threat group widely tracked as linked to APT10. It has been observed in operations targeting organizations in Japan. A notable design characteristic is environment gating for Windows Sandbox: the malware checks for artifacts associated with the sandbox’s default user context and is intended to execute only inside that isolated environment. This behavior aligns with campaigns in which attackers enabled Windows Sandbox on compromised hosts, mapped host folders into the sandbox, and launched malware within the sandbox to reduce visibility from host-based security controls. In observed operations, the sandboxed malware communicated with command-and-control infrastructure through Tor, combining remote access functionality with additional network-layer concealment. LilimRAT’s use reflects an intrusion tradecraft focused on post-compromise covert execution and defense evasion on Windows systems rather than broad commodity distribution.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
今回分析の対象とした検体「LilimRAT」は、「MirrorFace」と呼ばれる攻撃者グループによって利用されたことが観測されています。 この LilimRAT は OSS の RATツールである Lilith RAT をカスタマイズしたもので、WDAGUtilityAccount というユーザフォルダの存在を確認する処理が実装されており、このユーザフォルダがないと起動されないようになっていました。
今回分析の対象とした検体「LilimRAT」は、「MirrorFace」と呼ばれる攻撃者グループによって利用されたことが観測されています。 この LilimRAT は OSS の RATツールである Lilith RAT をカスタマイズしたもので、WDAGUtilityAccount というユーザフォルダの存在を確認する処理が実装されており、このユーザフォルダがないと起動されないようになっていました。
7 distinct techniques documented for this family, organized by ATT&CK tactic.
攻撃者は標的マシンを侵害したのち、Windows サンドボックスの機能を有効化します。... WSB ファイルを設置した後、ホストマシンを再起動します。... WSB ファイルの実行により、Windows サンドボックスの起動と同時に BAT ファイルの実行が行われ、BAT ファイル内に記載されていたスクリプトがサンドボックス内で実行されます。
この LilimRAT は OSS の RATツールである Lilith RAT をカスタマイズしたもので、WDAGUtilityAccount というユーザフォルダの存在を確認する処理が実装されており、このユーザフォルダがないと起動されないようになっていました。... Windows サンドボックス内では、デフォルトユーザ名として WDAGUtilityAccount が使われることから、今回解析対象にしたLilimRAT は Windows サンドボックス内でのみ動作することを想定して開発されたと考えられます。
この LilimRAT は OSS の RATツールである Lilith RAT をカスタマイズしたもので、WDAGUtilityAccount というユーザフォルダの存在を確認する処理が実装されており、このユーザフォルダがないと起動されないようになっていました。... Windows サンドボックス内では、デフォルトユーザ名として WDAGUtilityAccount が使われることから、今回解析対象にしたLilimRAT は Windows サンドボックス内でのみ動作することを想定して開発されたと考えられます。
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Customized open-source RAT variant used by MirrorFace; includes environment checks for Windows Sandbox (WDAGUtilityAccount) and terminates if not present, suggesting sandbox-only execution design.
MirrorFace が利用したカスタムRATで、OSSの Lilith RAT を改変したもの。WDAGUtilityAccount ユーザフォルダの存在確認を行い、Windows Sandbox 内でのみ動作するよう設計されている。サンドボックス内で起動後、C2サーバーと通信を開始し、侵害ホストの共有ファイルへアクセスしつつ遠隔操作を可能にする。
Named only in a cited prior report title as another malware family associated with broader APT10 reporting; no substantive discussion in this reference.
APT10 HUNTER RISE ver3.0: Repel new malware LODEINFO, DOWNJPIT and LilimRAT
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.