RATicate operated a long-running malware distribution service that delivered remote access trojans and information stealers through large-scale malspam campaigns, using shared command-and-control infrastructure and repeatable infection chains to support multiple customers. Researchers said the operation had been active since at least 2019 and functioned like a malware-as-a-service provider, distributing payloads including AgentTesla, Formbook, LokiBot, NetWire, and BetaBot against overlapping target sets.
In early 2020, the group upgraded its delivery chain by replacing custom NSIS installers with the commercial CloudEyE loader, a Visual Basic 6-based crypter that fetched encrypted second-stage payloads and complicated analysis and detection. Some campaigns used COVID-19-themed lures, and investigators linked the CloudEyE activity back to RATicate through infrastructure overlap and consistent tradecraft. After CloudEyE suspended service over abuse concerns on June 10, RATicate reverted to its earlier NSIS-based campaigns, while the crypter later resumed operations with added controls.

Pull IOCs and campaign context straight into your stack.
6 events from the most recent confirmed update back to the earliest known activity.
CloudEyE resumed operations on July 11 and said it would impose stricter internal controls, including use of a hardware ID grabber. The restart followed its earlier suspension over abuse concerns.
On June 10, CloudEyE announced that it had suspended sales because of abuse and refunded customers for unused license periods. Sophos noted that RATicate returned to NSIS-based campaigns after the shutdown.
An NSIS campaign on March 1, 2020 and a CloudEyE campaign on March 19, 2020 both used the same command-and-control URL, helping researchers link the two delivery methods to RATicate. This overlap supported attribution of the newer CloudEyE activity to the same operation.
In February 2020, RATicate began moving from NSIS installers to a Visual Basic 6-based loader associated with CloudEyE, also identified by Check Point as Guloader. Researchers observed overlap between NSIS and CloudEyE campaigns during this rollout, suggesting testing before a fuller switch.
Starting in November 2019, RATicate deployed payloads exclusively through custom NSIS installers. Sophos linked at least 14 campaigns between November 2019 and March 2020 to the same command-and-control infrastructure.
Sophos said RATicate had been spreading remote administration tools and information-stealing malware through malicious spam campaigns since at least 2019. The operation used email attachments masquerading as financial or business documents to infect victims.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.