AquilaRAT is a Rust-based remote access Trojan associated with the threat cluster tracked as Armored Likho and linked by multiple researchers to Eagle Werewolf activity. It has been used in espionage-oriented campaigns targeting government, industrial, and UAV-related victims, including operations distributed through compromised Telegram channels and themed lures related to Starlink registration or drone activity. AquilaRAT has also been referenced as an earlier malware family whose architecture overlaps with the later BusySnake Stealer, supporting cluster attribution through similarities in task handling, command-and-control design, and persistence conventions.
On compromised Windows systems, AquilaRAT operates as a backdoor that registers the host with command-and-control infrastructure, polls for tasks at short intervals, and executes commands through dedicated handlers. Reported tasking includes heartbeat or base communications, command execution, file upload, and file scanning or enumeration. Its design reflects a modular task-driven framework in which the malware receives instructions from the server and dispatches them to specialized handlers.
Observed deployments established persistence by masquerading as legitimate Microsoft software, including installation as a Windows service under a Microsoft-themed name. Reporting also notes similarities between AquilaRAT and BusySnake in scheduled-task naming and persistence style, indicating a broader operator preference for Microsoft-themed masquerading. In Eagle Werewolf intrusions, AquilaRAT was deployed alongside additional tooling such as Rust and Go droppers and Go2Tunnel, with the broader intrusion set also creating hidden local accounts and enabling SSH tunneling for sustained operator access.
AquilaRAT is best characterized as a Windows backdoor or RAT used for persistent remote access and post-compromise control in targeted campaigns. Its known use by Armored Likho or Eagle Werewolf places it within a toolkit oriented toward long-term access, host management, and follow-on collection rather than smash-and-grab commodity crime.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Similarités architecturales avec AquilaRAT (handlers, endpoints C2, mécanismes de persistance)
Similarités architecturales avec AquilaRAT (handlers, endpoints C2, mécanismes de persistance)
24 distinct techniques documented for this family, organized by ATT&CK tactic.
The starting point of the attack chain is a spear-phishing email that uses lures related to official government notices or social programs to distribute a RAR archive containing EXE binaries that serve as droppers for additional payloads retrieved from a GitHub repository, including the stealer payload.
Второй скрипт, run.vbs, предназначен для запуска module.pyw и используется для обеспечения закрепления в системе при помощи запланированной задачи... Эта задача обеспечивает запуск полезной нагрузки — BusySnake Stealer — каждые пять минут.
Il est persisté via une tâche planifiée (toutes les 5 minutes) ... Une version plus récente a été identifiée, intégrant : Création de tâches planifiées via COM object ( Schedule.Service ) au lieu de schtasks
researchers linked it to earlier activity involving AquilaRAT... Both use comparable C2 endpoints to report task execution
run-script.ps1, a PowerShell script to load and execute code via PowerShell. The file contains: powershell -w hidden -ep bypass -c "I''E''X...DOWNLOADDaTa(...)"
Cmd, performs the following actions: cmd /K chcp 65001 —sets the encoding chcp-65001, and then executes powershell <command>.
Второй скрипт, run.vbs, предназначен для запуска module.pyw и используется для обеспечения закрепления в системе при помощи запланированной задачи... Эта задача обеспечивает запуск полезной нагрузки — BusySnake Stealer — каждые пять минут.
Второй скрипт, run.vbs, предназначен для запуска module.pyw и используется для обеспечения закрепления в системе при помощи запланированной задачи... Эта задача обеспечивает запуск полезной нагрузки — BusySnake Stealer — каждые пять минут.
Armored Likho utilizes a modular and evolving toolkit that includes obfuscated remote access trojans (RATs)...
The dropper contains the EchoGather payload, which is Base64-encoded and XOR-encrypted.
BattleFlight-Install-v11.0.3.exe, a C# dropper disguised as an installer for a drone pilot training simulator.
Its primary goal is to establish communication with a C2 server and then await incoming instructions.
Обновленные конечные точки ... /api/v1/client/{Config.CLIENT_ID}/commands/ ... /tasks/ ... /files/
31 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a related malware family with architectural similarities to BusySnake, including handlers, C2 endpoints, and persistence mechanisms.
A previously used malware family associated with Armored Likho and referenced as structurally overlapping with the current campaign's tooling.
A previously observed RAT linked to earlier activity attributed to Armored Likho; it shares structural similarities with BusySnake, including comparable C2 reporting and scheduled-task persistence masquerading as Microsoft utilities.
Referenced as a similar Trojan whose architecture resembles BusySnake, with tasking from a command-and-control server and execution via handlers.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.