Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
A cheap, Telegram-controlled remote access trojan (RAT) dubbed Millenium RAT has infected over 60,000 Windows devices across more than 160 countries... Millenium RAT is sold cheaply as malware-as-a-service (MaaS) and uses the Telegram Bot API to receive commands.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
In one campaign, victims received a shortcut disguised as a PDF, which triggered PowerShell silently and fetched a decoy document alongside the RAT payload, opening the document in the foreground as cover.
The data is Base64-encoded and protected with a custom XOR algorithm, with extra random data added to change the file hash and bypass signature-based detection.
As a full RAT, Millenium RAT can steal data from browsers, log keystrokes, capture screenshots and record audio.
As a full RAT, Millenium RAT can steal data from browsers, log keystrokes, capture screenshots and record audio.
It communicates with operators through the Telegram Bot API, disguising command-and-control traffic as normal web activity
59 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A C++-based remote access trojan sold as a malware-as-a-service offering. It uses the Telegram Bot API for command-and-control instead of dedicated C2 servers and supports credential theft, keylogging, screenshot and audio capture, arbitrary code execution, and full system compromise.
A Telegram-controlled remote access trojan sold as malware-as-a-service. It was rewritten from .NET to native C++ to improve evasion and can steal browser data, log keystrokes, capture screenshots, record audio, download and execute files, and in some cases encrypt files or trigger a blue screen.
Millenium RAT is a Windows-focused malware-as-a-service remote access trojan that uses social-engineering lures and trojanized tools for delivery. It communicates via the Telegram Bot API, loads an encrypted embedded configuration, establishes persistence through %APPDATA% and a Run registry key, and supports credential and cookie theft, screenshots, webcam capture, audio recording, keylogging, Telegram/Discord session theft, and file encryption.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.