RATicate is a malware distribution threat actor active since at least 2019 that conducts malspam campaigns to deliver remote access trojans and information-stealing malware. The group is associated with multi-stage delivery chains that initially relied on custom NSIS-based installers and later shifted to the CloudEyE loader, also identified in some reporting as GuLoader, before reverting to NSIS activity after CloudEyE service disruptions. RATicate has been assessed as likely operating in a malware-as-a-service role, providing delivery and command-and-control infrastructure used to deploy multiple commodity malware families rather than being tied to a single payload. RATicate campaigns have delivered malware including Agent Tesla, Formbook, LokiBot, NetWire, BetaBot, Bladabindi/njRAT, BlackRAT, and Remcos. Infection chains commonly used phishing emails with business-themed lures such as financial transaction documents, and later included COVID-19-themed social engineering. In its NSIS campaigns, the actor used heavily packed installers with numerous junk files to hinder analysis, abused the NSIS System.dll plugin to invoke malicious loader components, decrypted staged shellcode and loader modules from embedded or dropped data, and injected final payloads into child processes using section-mapping techniques. In CloudEyE-based operations, RATicate used encrypted second-stage payload retrieval and process injection, complicating static analysis and payload recovery. The actor’s activity shows consistent use of shared infrastructure, repeated loader architecture, overlapping victimology, and recurring payload families across multiple campaign waves. Observed targeting has focused on industrial and critical-infrastructure-related organizations across Europe, the Middle East, and Asia, with specifically identified victims in Romania, Kuwait, South Korea, the United Kingdom, Switzerland, and Japan. The group’s operational pattern, including distinct campaign clustering and reuse of delivery infrastructure across different malware families, supports the assessment that RATicate functions primarily as a distribution service for other criminal operators. Its dominant motivation is financial gain.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
15 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
9 malware families attributed to this actor across reporting.
4 additional families tracked in Mallory.
55 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malspam-driven malware distribution operation assessed as likely Malware-as-a-Service, delivering RAT and infostealer payloads via NSIS installers and later the CloudEyE loader, including COVID-19 themed lures and shared C2 infrastructure across campaigns.
Mentioned as a past user of njRAT for information theft and espionage.
Runs serial malspam campaigns delivering NSIS-based installers that use a custom multi-stage loader (DLL + shellcode) to decrypt and inject various commodity RAT/infostealer payloads; targets industrial/critical-infrastructure-adjacent organizations across Europe, the Middle East, and South Korea, and later used COVID-19 lures with different loaders/packers.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.