Multiple investigations detailed STRRAT, a Java-based remote access trojan, being delivered through phishing emails, malicious Office documents, JAR attachments, and even trojanized MSI installers with appended JAR content. Analysts found operators using obfuscation and packaging tricks to hide the malware, including embedding ZIP/JAR archives after valid MSI data, disguising payloads inside spam-delivered attachments, and hosting follow-on stages on services such as AWS and GitHub. In one infection chain, a malicious Excel file downloaded a large ZIP archive over HTTP and unpacked both STRRAT and a bundled Java Runtime Environment into a deceptive Windows path, while another campaign used a Java downloader to deploy both VCURMS and STRRAT.
The malware was reported to support credential theft, keylogging, file management, remote command execution, reverse proxying, and remote desktop abuse through RDP-related components, with some samples also carrying a crude .crimson file-renaming ransomware module. Researchers noted that STRRAT can run even on systems without Java by installing its own JRE, reducing a traditional barrier to infection. Observed infrastructure included DuckDNS-based command-and-control, direct IP communications, Proton Mail for VCURMS tasking, and encrypted STRRAT configurations that exposed identifiers such as Khonsari, underscoring continued evolution in both delivery methods and post-compromise capability.

Pull IOCs and campaign context straight into your stack.
7 events from the most recent confirmed update back to the earliest known activity.
FortiGuard Labs described a phishing campaign using a malicious Java downloader from AWS-hosted infrastructure to fetch and execute both the VCURMS RAT and STRRAT, with multiple obfuscation layers and email-based command and control for VCURMS.
A malware analysis blog examined a sample masquerading as a legitimate MSI installer and found appended ZIP/JAR content containing Java classes under the carLambo package, concluding the file carried STRRAT hidden after valid MSI data.
FortiGuard Labs analyzed a phishing campaign that impersonated Maersk Shipping and delivered STRRAT directly as a Java JAR inside ZIP attachments, rather than via an intermediate dropper. The report documented persistence, credential theft, keylogging, HRDP-based remote control, pseudo-ransomware behavior using the .crimson extension, and campaign infrastructure including acalpulps.com, ftqplc.in, 198.27.77.242, and jbfrost.live.
SANS ISC published analysis of a 2021 STRRAT infection chain showing that a macro-enabled Excel lure downloaded a 72.1 MB ZIP archive containing both STRRAT and JRE 8 Update 261, allowing the Java RAT to run even if Java was not installed on the victim host.
A malicious Excel spreadsheet associated with a STRRAT infection chain was submitted to bazaar.abuse.ch. The sample used macros to fetch a ZIP archive, unpack a bundled JRE and STRRAT JAR, and run the malware from a deceptive C:\User directory.
G DATA analyzed a Java-based STRRAT 1.2 campaign delivered through spam email with a malicious JAR attachment, detailing its VBScript-based installer, persistence, credential theft, remote access features, and a ransomware component that only renames files with a .crimson extension.
Securityinbits documented a malware delivery technique in which Ratty and Adwind JAR payloads were appended to signed MSI files, and released the 'jar_in_msi' YARA rule to detect MSI files containing embedded JAR/ZIP structures. The post also shared related indicators of compromise and extraction examples for the polyglot-style payloads.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 52 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
7 references tracked. Mallory keeps watching after this page renders.
fortinet.com
Open sourceforensicitguy.github.io
Open sourcefortinet.com
Open sourceisc.sans.edu
Open sourcegdatasoftware.com
Open sourcesecurityinbits.com
Open sourcesecurityscorecard.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.