njRAT Golden Edition is a 2017-era variant of the njRAT family, attributed in the source content to Hassan Amiri and based on njRAT v0.7. It introduces configuration obfuscation, multiple payload delivery methods, and additional anti-analysis behavior, while retaining unencrypted command-and-control communications. Commands and data are transmitted in plaintext and can be observed directly on the wire. The malware obfuscates its C2 IP address and port using Base64 plus character substitution with Unicode symbols; at runtime it reverses the substitution and decodes the Base64 to recover the original configuration. The content explicitly characterizes this as weak obfuscation rather than true encryption.
The payload’s main function declares two threads, and its ko() function is described as nearly identical to njRAT v0.7 with modifications. The variant adds new commands relative to njRAT v0.7. The controller application is obfuscated but can be de-obfuscated, and optional payload compression uses mpress. Two downloader modes are described: a Normal downloader that retrieves a payload from a remote web server, writes it to %TEMP%\svchost.exe, and executes it; and an EntryPoint downloader that downloads payload bytes, loads them with Assembly.Load, and executes them in memory. The content also describes a separate Anti-Process builder associated with Golden Edition that is not a C2-connected RAT payload; instead, it repeatedly kills configured processes at a set interval, copies itself to the Startup folder, and launches the copied executable with argument '0'.
The analysis identifies implementation flaws. A malformed firewall-related command appears to replace netsh with Hassan, causing execution failure; Process Monitor reportedly showed NAME_NOT_FOUND. This is assessed as an implementation mistake that makes part of the installation routine ineffective. Additional notable indicators and artifacts directly mentioned in the content include frequent appearance of the keyword Hassan in network traffic and code, use of plaintext protocol traffic visible in Wireshark, and the %TEMP%\svchost.exe path used by the Normal downloader.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
The persistence and hidden payload functionalities are shown below... I found that this payload does not have functionality for connection. It is a malware killing specified processes every specified interval... Copy self to Startup Folder (NomeStartUp.exe) Start copied executable with argument '0'.
The persistence and hidden payload functionalities are shown below... I found that this payload does not have functionality for connection. It is a malware killing specified processes every specified interval... Copy self to Startup Folder (NomeStartUp.exe) Start copied executable with argument '0'.
The author implemented a customized obfuscator to protect the IP address and port number of the C2 server. The mechanism works as follows: Encode the original string using Base64 Replace specific characters with Unicode symbols (Chinese, Korean, Hindi) At runtime, the payload: Reverses the character substitution Decodes Base64 Restores the original configuration.
njRAT Golden Edition uses mpress to compress the payload if this functionality is enable: mpress.exe
The underlying mechanism is: it downloads the file bytes from the remote web server, loads it into memory and executes it in memory. Start: EntryPoint Downloader Download Payload via WebClient.DownloadData Load Payload into Memory (Assembly.Load) Invoke Payload EntryPoint Payload is running in memory.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A named njRAT variant whose code architecture appears to have been used as the basis for njRAT Danger Edition 2018.
A remote access trojan variant of the njRAT family that adds weak Base64-and-character-replacement C2 configuration obfuscation, multiple payload delivery methods including in-memory execution, downloader functionality, persistence features, and anti-analysis behavior. Its network communication remains unencrypted and some functions contain implementation flaws.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.