Cabbage RAT, also known as CageyChameleon, is a multi-stage remote access trojan associated with the CryptoMimic intrusion set and later financially motivated North Korean social-engineering activity overlapping with UNC1069/Bluenoroff reporting. It has been used primarily against financial organizations, especially cryptocurrency and Web3 targets, as part of intrusion chains focused on credential access, digital-asset theft, and broader post-compromise control.
Historically, Cabbage RAT has been delivered through targeted social-engineering operations, including spearphishing emails and LinkedIn messages that lead victims to malicious archives containing shortcut-based launchers and staged VBScript payloads. More recent campaigns used fake online meeting lures impersonating conferencing platforms and ClickFix-style prompts that trick victims into executing commands themselves. The malware has also been observed in payload chains tailored to the victim operating system.
Early documented Windows variants were implemented in VBScript and deployed in stages commonly referred to as Cabbage RAT-A, -B, and -C. These stages performed environment checks, filtered victims, established persistence, and maintained command-and-control over HTTP-based communications. Cabbage RAT could collect host information, enumerate processes, periodically beacon to its controller, execute server-supplied VBScript, run shell commands, list directories, upload and download files, delete files, and adjust execution intervals. Operators used it interactively alongside native system utilities for reconnaissance and follow-on actions.
The malware family also demonstrated defense-evasion behavior. Observed variants checked for security products and altered execution accordingly, and later campaigns added Windows Defender exclusions. Persistence has been achieved through Startup-folder shortcuts and related staged launchers. In broader intrusion chains, Cabbage RAT has served as a delivery mechanism for additional tooling including browser information stealers, credential theft components, and other RAT modules.
Updated variants observed in 2026 expanded beyond Windows, with payloads built specifically for Windows, macOS, and Linux victims. On Windows, newer variants collected system metadata and enumerated installed browser extensions, likely to identify cryptocurrency wallet extensions and other high-value targets. Linux samples reportedly mirrored the Windows command-and-control logic and staging behavior. These developments indicate an evolution from a VBScript-centric Windows RAT into a cross-platform malware family supporting financially motivated operations against cryptocurrency ecosystems.
Cabbage RAT has been assessed as part of campaigns showing multiple overlaps with Lazarus-linked tradecraft, though definitive attribution of the malware family itself beyond the reported operator clusters remains unsettled.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Cabbage RAT-C was downloaded and executed... Browser Info Stealer was downloaded and executed... msoRAT was downloaded and executed.
Cabbage RAT-C was downloaded and executed... Browser Info Stealer was downloaded and executed... msoRAT was downloaded and executed.
Validin researchers identified and analyzed the full attack chain in April 2026, revealing the scale and technical complexity of the campaign’s supporting infrastructure. They found that payloads are built specifically for the victim’s operating system, whether Windows, macOS, or Linux, and that the malware used appears to be updated variants of Cabbage RAT, also known as CageyChameleon.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
The majority of CryptoMimic attacks start with an email containing a link to a website or a LinkedIn message.
In most cases, the link to the website is shortened by Bitly. As soon as a user opens the link, a file is downloaded from a cloud service such as OneDrive via a server prepared by the group.
The attackers make first contact through LinkedIn and Telegram, sometimes using previously compromised accounts to appear more legitimate. They then share scheduling links via Calendly to set up meetings on fake platforms that closely copy the look and feel of Zoom, Google Meet, and Microsoft Teams.
On Windows machines, the ClickFix prompt instructs victims to press Win + X followed by “A” to open a terminal with administrator privileges, then paste and run a set of commands. These commands pull down two separate PowerShell scripts from attacker-controlled servers.
The attacker launched several Windows commands on the victim host via these RATs... cmd.exe, cmdkey.exe, copy.exe, find.exe, ipconfig.exe, net.exe, netstat.exe, ping.exe, systeminfo.exe, whoami.exe, wevutil.exe.
On Linux systems, victims are instructed to press Ctrl + Alt + T... and then they are prompted to paste and execute the following commands which include fetching and running an ELF downloader.
The VBScript embedded in the website is then read and executed by mshta.exe. The script subsequently downloads other scripts and finally gains functionality as a RAT.
In many cases, the name of the LNK file is something like ‘Password.txt.lnk’.
CryptoMimic is very careful and it is extremely difficult to observe the attack under virtual environments including in a sandbox.
The RAT communicates with its command-and-control (C2) server to: Exfiltrate collected host data Enumerate running processes (getProc)
The VBScript payload is an updated variant of Cabbage RAT that begins by collecting system details including the current username, hostname, operating system version, and installed browser extensions.
20 → Download, Base64-decode, and XOR-decrypt a secondary VBS payload, which is then executed in memory.
The first script downloads a VBScript file, writes it to the temporary directory, and executes it twice using wscript.exe, while also adding the C:\Users directory to Windows Defender’s exclusion list and restarting the WinDefend service to suppress any alerts.
49 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote access trojan used in a North Korean social-engineering campaign targeting cryptocurrency and Web3 professionals. On Windows, an updated VBScript variant collects system details such as username, hostname, OS version, and installed browser extensions, adds persistence via a .lnk shortcut in the Startup folder, communicates with a C2 server, and can retrieve a secondary encrypted payload. The malware also appears tailored by operating system and is aimed at stealing digital assets, including by identifying cryptocurrency wallet browser extensions.
An updated cross-platform RAT used in UNC1069 fake meeting campaigns. It is delivered via ClickFix-style lures and OS-specific downloaders, performs system reconnaissance, exfiltrates host data, establishes persistence in some Windows variants, communicates with C2 over HTTP POST, can download and execute additional payloads, enumerate processes, and collect Chrome extensions likely to identify cryptocurrency wallets.
A staged VBScript remote access trojan delivered in multiple phases. Cabbage RAT-B profiles the victim and reports system/task information to C2, while Cabbage RAT-C provides interactive control, file and directory listing, command execution, upload/download, and information theft support.
A multi-stage VBScript remote access trojan used by CryptoMimic. Stage A fetches and executes code from C2, stage B periodically sends victim information and executes tasks from C2, and stage C is a fuller-featured RAT used to run commands, manage files, execute VBScript, and drive later-stage payload delivery.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.