NonEuclid RAT, also tracked as NONEUCLID, SheetRAT, LiberiumRAT, and ShadowRoot, has been reported infecting devices worldwide while offering attackers full remote control of compromised Windows systems. Researchers describe the malware as a C#/.NET Framework 4.8 trojan with layered evasion and persistence features, including a rootkit, UAC bypass, obfuscation, anti-debugging, virtualization checks, dynamic Windows API invocation, and mechanisms to bypass Windows Defender and AMSI. It reportedly maintains access through scheduled tasks and registry changes, drops payloads into user AppData directories, and can reconnect to command-and-control infrastructure over TCP, with some activity also tied to Discord webhook-based C2.

Pull IOCs and campaign context straight into your stack.
2 events from the most recent confirmed update back to the earliest known activity.
A later technical analysis described NonEuclid RAT as a C#/.NET remote access trojan with defense-evasion, persistence, privilege-escalation, anti-analysis, and TCP-based command-and-control features. The report also documented ransomware behavior, including AES file encryption, the .NonEuclid extension, persistence via scheduled tasks and registry changes, AMSI bypass, and sample indicators.
A report highlighted NONEUCLID, also referred to as SheetRAT, LiberiumRAT, or ShadowRoot, as a remote access trojan that had infected devices worldwide. The report described impacts on both individuals and organizations and noted capabilities including rootkit functionality, persistence, UAC bypass, obfuscation, anti-debugging, botnet features, and Discord webhook-based command-and-control.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.