AquilaRAT is a Rust-based remote access Trojan associated with the Armored Likho threat actor, also referred to as Eagle Werewolf. It has been used in espionage-oriented campaigns targeting government, industrial, and drone-related victims, including operations distributed through compromised Telegram channels and themed lures related to Starlink registration and UAV activity. The malware has been deployed through multi-stage infection chains involving Rust and Go droppers and installed for persistence as a Windows service masquerading as legitimate software.
AquilaRAT follows a task-driven architecture in which an infected host registers with command-and-control infrastructure, polls for instructions at short intervals, and executes functionality through dedicated handlers. Reported capabilities include remote command execution, file upload, and file scanning or enumeration. The malware also generates a machine identifier from host hardware and system attributes, a design element later observed in other Armored Likho tooling. Its persistence and command structure show architectural similarities to BusySnake Stealer, and its cryptographic routines and configuration handling have been reused in later malware attributed to the same actor.
The malware is notable as part of a broader in-house ecosystem developed by Armored Likho for long-term access and intelligence collection. Shared encryption methods, host-identification logic, persistence patterns, and command-and-control design link AquilaRAT to subsequent Rust-based implants and espionage tooling used by the group.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Для шифрования этой конфигурации применяется тот же алгоритм и ключ, которые ранее встречались в AquilaRAT из арсенала Armored Likho.
Worth noting: other Armored Likho tools, AquilaRAT included, use this same hashing algorithm... Older AquilaRAT samples use this exact same algorithm and key.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
The starting point of the attack chain is a spear-phishing email that uses lures related to official government notices or social programs to distribute a RAR archive containing EXE binaries that serve as droppers for additional payloads retrieved from a GitHub repository, including the stealer payload.
Второй скрипт, run.vbs, предназначен для запуска module.pyw и используется для обеспечения закрепления в системе при помощи запланированной задачи... Эта задача обеспечивает запуск полезной нагрузки — BusySnake Stealer — каждые пять минут.
Il est persisté via une tâche planifiée (toutes les 5 minutes) ... Une version plus récente a été identifiée, intégrant : Création de tâches planifiées via COM object ( Schedule.Service ) au lieu de schtasks
researchers linked it to earlier activity involving AquilaRAT... Both use comparable C2 endpoints to report task execution
The algorithms match down to the PowerShell commands used to collect system information.
Cmd, performs the following actions: cmd /K chcp 65001 —sets the encoding chcp-65001, and then executes powershell <command>.
Второй скрипт, run.vbs, предназначен для запуска module.pyw и используется для обеспечения закрепления в системе при помощи запланированной задачи... Эта задача обеспечивает запуск полезной нагрузки — BusySnake Stealer — каждые пять минут.
Второй скрипт, run.vbs, предназначен для запуска module.pyw и используется для обеспечения закрепления в системе при помощи запланированной задачи... Эта задача обеспечивает запуск полезной нагрузки — BusySnake Stealer — каждые пять минут.
Armored Likho utilizes a modular and evolving toolkit that includes obfuscated remote access trojans (RATs)...
The dropper contains the EchoGather payload, which is Base64-encoded and XOR-encrypted.
BattleFlight-Install-v11.0.3.exe, a C# dropper disguised as an installer for a drone pilot training simulator.
Its primary goal is to establish communication with a C2 server and then await incoming instructions.
Обновленные конечные точки ... /api/v1/client/{Config.CLIENT_ID}/commands/ ... /tasks/ ... /files/
Also put to use in the attacks is Go2Tunnel to establish a reverse SSH tunnel to a command-and-control (C2) server using a private key.
41 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote access trojan previously associated with Armored Likho; mentioned here because its encryption algorithm and key overlap with the new malware campaign.
A previously documented Armored Likho remote access tool referenced for code and tradecraft overlap with the Still Toolkit, including sysmarker generation and Dead Drop Resolver encryption/key reuse.
Previously observed Armored Likho remote access tool referenced for code and implementation overlap with the Still modules, including sysmarker generation and encrypted dead-drop resolver logic.
Previously documented Armored Likho malware referenced for code and infrastructure overlap with the Still Toolkit, including shared sysmarker generation and Dead Drop Resolver encryption/keying.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.