AstarionRAT is a Windows remote access trojan first publicly documented in February 2026. It has been deployed as a follow-on payload by the Matanbuchus 3.0 malware-as-a-service loader in ClickFix social-engineering campaigns. The execution chain uses DLL sideloading, an embedded Lua interpreter, and reflective in-memory loading to launch the RAT while reducing on-disk artifacts.
AstarionRAT implements 24 operator commands supporting credential theft, credential logon and token impersonation, shell execution with output capture, file and process operations, SOCKS5 proxying, port scanning, and reflective loading of additional operator-supplied payloads. It gathers host metadata including privilege context and communicates with command-and-control infrastructure using RSA-encrypted metadata traffic disguised as application telemetry. Documented intrusions involving its deployment included rapid hands-on-keyboard activity, PsExec-based movement toward Windows servers and domain controllers, rogue-account creation, and attempts to weaken Microsoft Defender protections. No specific threat actor attribution has been established for AstarionRAT.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
30 distinct techniques documented for this family, organized by ATT&CK tactic.
"established persistence via a scheduled task named Application Maintenance"
"...leads to the execution of a PowerShell command... fetch a second-stage PowerShell script..."
"Shell Execute... spawns CMD... captures output"; "wraps in CMD /C <command>"
"After decryption, the Lua script is straightforward; its only purpose is to decode and execute embedded shellcode."
"walking the Process Environment Block to locate ntdll.dll and resolve four native API functions by hash"; "All API access is routed through an internal hash dispatch function"
"The malware leverages the persistent “ClickFix” social engineering tactic, which tricks users into manually executing malicious commands... Victims are presented with deceptive prompts instructing them to copy and paste specific PowerShell or Run dialog commands."
“...extract a password-protected archive (TMP412.7z with password...)... heavily padded with junk code... strings... encrypted... ChaCha20...”
"Steal Token... duplicates its token... applies it to the current thread"; "Credential Logon... LogonUserA... impersonates the resulting token"; "Revert to Self"
"includes... the local IP address obtained via WSAIoctl"
"tab-delimited string of the computer name, username, and process filename"
Step 5 - C2 Registration + EDR Enumeration T1071.001, T1518.001 | Malware Main module registers with C2 via Protobuf-over-HTTPS (ChaCha20 encrypted, 32-byte key + 12-byte nonce prepended). C2 traffic masquerades as Skype Desktop application.
"...AstarionRAT... including credential theft and SOCKS5 proxying."
"...msiexec command that fetches a payload from a newly registered domain."
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote access trojan delivered in current Matanbuchus campaigns. It supports 24 commands including shell execution, SOCKS5 proxying, port scanning, credential theft, reflective code loading, and file operations, with C2 traffic disguised as application telemetry.
A remote-access trojan delivered by Matanbuchus that supports shell execution, SOCKS5 proxying, port scanning, credential theft, file operations, and reflective code loading. Its C2 uses RSA encryption masquerading as application telemetry.
A novel custom implant mentioned in connection with a prior ClickFix intrusion.
Remote access trojan distributed via ClickFix social-engineering; supports credential theft, SOCKS5 proxying, port scanning, reflective code loading, shell execution, and RSA-encrypted C2 disguised as application telemetry.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.