Researchers documented continued use of njRAT (also known as Bladabindi) in targeted intrusion campaigns alongside other commodity and custom remote access trojans. Cisco Talos said the SideCopy APT, which targets government personnel and other entities in India, incorporated njRAT into multi-stage infection chains that often begin with malicious .LNK files and progress through HTAs and loader DLLs before deploying RATs and post-compromise plugins for credential theft, file enumeration, and keylogging. ESET separately reported Operation Spalax, a phishing-driven campaign aimed at Colombian government institutions and private-sector organizations, especially in the energy and metallurgical sectors, where attackers used shortened links, RAR archives, and multiple droppers to install njRAT, Remcos, and AsyncRAT for surveillance and remote control.
A technical analysis of an njRAT 0.6.4 sample tied to the campaign ID splitgateukrayna showed how the malware persists by copying itself to %AppData%\services64.exe, creating a Run registry key, adding a Windows Firewall exception, and using the mutex 49e91d08e684b1770e0cefa60401157a. The sample connected to 44gang44.duckdns[.]org on port 2222, profiled infected systems, and supported a broad set of capabilities including hidden shell execution, keylogging, screenshot capture, registry manipulation, plugin loading, payload download-and-execute, self-update, and uninstall. Across the reported campaigns, njRAT remained a flexible, low-cost espionage tool used to establish persistence, collect victim data, and enable long-term remote access.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
A public analysis examined an njRAT v0.6.4 sample associated with the campaign ID "splitgateukrayna," detailing persistence, host profiling, C2 communications to 44gang44.duckdns[.]org:2222, and capabilities including keylogging, screenshots, plugin loading, and payload execution.
Alongside its SideCopy report, Cisco Talos published Snort SIDs 57842 through 57849 and ClamAV signatures covering malware including njRAT, EpicenterRAT, Lilith, DetaRAT, ReverseRAT, ActionRAT, and AllakoreRAT.
Cisco Talos reported increased SideCopy activity targeting government personnel in India and documented the group's use of njRAT, Allakore, Lilith, Epicenter, and four newly identified custom RAT families: DetaRAT, ReverseRAT, MargulasRAT, and ActionRAT.
ESET disclosed Operation Spalax as an ongoing campaign targeting Colombian organizations and documented its phishing lures, delivery chains, infrastructure, and use of commodity RATs including njRAT.
ESET observed at least 24 IP addresses and around 70 active domains supporting the attackers' infrastructure in the second half of 2020, with new domains registered regularly. Some infrastructure used dynamic DNS and likely compromised devices as proxies.
ESET observed several attacks in 2020 that exclusively targeted Colombian government institutions and private companies, especially in the energy and metallurgical sectors. The campaign used phishing to deliver RATs including Remcos, njRAT, and AsyncRAT for surveillance.
Trend Micro published a report in July 2019 describing activity with similarities in phishing and parts of the infrastructure later seen in Operation Spalax, though it linked that activity to cybercrime rather than espionage.
QiAnXin published a report in February 2019 describing operations connected to an APT that had been active since at least April 2018. ESET later noted overlaps between this earlier activity and Operation Spalax.
Cisco Talos said SideCopy had used commodity RATs such as njRAT, Lilith, and Epicenter since as early as 2019, alongside its custom malware development.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
cybergeeks.tech
Open sourceblog.talosintelligence.com
Open sourcewelivesecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.