Palo Alto Networks Unit 42 reported that Blackremote RAT, a newly emerged commodity remote access trojan, was advertised on underground forums by an actor using the handles Speccy and Rafiki. The malware was sold with supporting infrastructure including a builder, manager, and client component, and offered capabilities such as password recovery, keylogging, remote desktop control, scripting, and downloader functions, making it a full-featured tool for remote compromise.
Researchers said Blackremote moved quickly from sale to active use, with nearly 50 samples tied to more than 2,200 attack sessions observed against Palo Alto Networks customers within about a month of its launch. One major campaign distributed the sample doc00190910.exe by email and used the command-and-control domain renaj.duckdns[.]org at 103.200.6[.]79, accounting for more than 1,800 sessions across multiple industries worldwide. Unit 42 also said the operator behind Blackremote was an 18-year-old from Sweden and that identifying information had been provided to the relevant authorities.

Pull IOCs and campaign context straight into your stack.
7 events from the most recent confirmed update back to the earliest known activity.
A major Blackremote campaign distributing the sample doc00190910.exe by email peaked between September 9 and September 11, 2019. The malware communicated with renaj.duckdns[.]org at 103.200.6[.]79 and ultimately accounted for more than 1,800 observed attack sessions.
Unit 42 identified Blackremote RAT as a previously undocumented commodity remote access trojan in September 2019. The report characterized it as a newly emerged malware offering with extensive surveillance and remote-control capabilities.
During the same week as the forum promotion, the actor posted a YouTube setup video for Blackremote RAT. The video description linked to speccy[.]dev and promoted the malware as fully runtime undetected while advertising a FUD crypter.
An actor using the handles Speccy and Rafiki started advertising Blackremote RAT on underground forums during the first week of September 2019. The promotion directed buyers to blackremote[.]pro and also shared the Discord handle Speccy#0100.
The domain blackremote[.]pro, used as the malware's sales site, was registered. This infrastructure later supported promotion and sales of Blackremote RAT.
Unit 42 stated that the actor behind Blackremote was an 18-year-old from Sweden and that his identity was provided to the appropriate authorities. The source does not explicitly anchor when that handoff occurred.
Within about a month of launch, Unit 42 observed nearly 50 Blackremote samples across more than 2,200 attack sessions against Palo Alto Networks customers. The activity affected organizations across multiple industries worldwide, showing the malware was already in operational use.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 49 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.