U.S. and international authorities dismantled key parts of the Warzone RAT malware ecosystem, seizing warzone.ws and three related domains and unsealing indictments against alleged operators and support actors in Malta and Nigeria. The U.S. Department of Justice said the malware was marketed as a remote access trojan capable of browsing files, capturing screenshots, logging keystrokes, stealing credentials, and covertly accessing webcams, and that FBI analysis tied the tool to attacks on victim systems in Massachusetts.
Warzone RAT had been widely distributed through malicious Office documents and multi-stage infection chains using JavaScript and PowerShell, with later samples adding stealth features such as process hollowing, task-scheduler persistence, process injection, and a UAC bypass via ComputerDefaults.exe. Security researchers described the malware as a malware-as-a-service offering designed to evade detection while enabling surveillance and data theft on compromised Windows hosts.

Pull IOCs and campaign context straight into your stack.
8 events from the most recent confirmed update back to the earliest known activity.
Authorities arrested Daniel Meli in Malta and Prince Onyeoziri Odinakachi in Nigeria in a coordinated international operation targeting alleged Warzone RAT sales and support actors.
A federal grand jury in the District of Massachusetts indicted Prince Onyeoziri Odinakachi for allegedly conspiring to support computer intrusion offenses connected to Warzone RAT.
A federal grand jury in the Northern District of Georgia indicted Daniel Meli on charges tied to allegedly selling and supporting Warzone RAT and related malware services.
Uptycs said it had previously identified WarzoneRAT using a Windows User Account Control bypass technique via ComputerDefaults.exe in November 2020.
Charging documents allege that since at least 2012, Daniel Meli offered malware products and services to cybercriminals through online hacking forums, including selling Warzone RAT and previously Pegasus RAT.
The U.S. Department of Justice announced an international operation that seized warzone.ws and three related domains used to sell Warzone RAT, with coordination through Europol and assistance from multiple countries.
Uptycs analyzed a WarzoneRAT infection chain delivered through a malicious document, JavaScript, and PowerShell, with the malware executed through process hollowing for defense evasion and persistence.
A Quick Heal blog post described Warzone RAT as a trojan malware that steals data and is triggered from various Office documents.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
3 references tracked. Mallory keeps watching after this page renders.
justice.gov
Open sourceuptycs.com
Open sourceblogs.quickheal.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.