ComRAT, also known as Agent.BTZ, is a long-running Windows malware family associated with the Turla espionage group. It is best characterized in later reporting as a sophisticated user-mode remote access trojan used in state-sponsored operations, while earlier Agent.BTZ activity has also been described as a self-replicating worm. The malware has been linked historically to the 2008 U.S. military network intrusion commonly referred to as the Pentagon breach, and later variants have been tied to Turla operations targeting diplomatic and governmental entities, including ministries and conference-related organizations in Europe.
ComRAT supports persistent access and post-compromise control on infected Windows systems. Observed variants use PowerShell loaders that execute at user logon and can be launched via scheduled tasks. The malware has stored encrypted orchestrator components in the Windows Registry and can keep PowerShell script content there as part of its persistence and staging design. It can execute PowerShell scripts from memory or disk, load PE payloads from memory or the filesystem, and start them via native Windows process-creation APIs.
The malware includes multiple defense-evasion and stealth features. It has used per-machine secrets to decrypt core payload components and XOR-based protection for its communications module. It has also injected its orchestrator component into explorer.exe and placed its communications module inside the victim’s default browser so command-and-control traffic blends with normal user activity. Some variants check local date and time and restrict activity to business hours, likely to reduce suspicion.
ComRAT also performs host and network reconnaissance. Documented behavior includes collecting the current username and gathering local network adapter information such as IP and MAC addressing and related network configuration details. These capabilities support victim profiling and operator tasking after compromise.
The malware is part of the broader Turla ecosystem and has been discussed alongside Snake/Uroburos. Reporting has noted technical and historical links between Agent.BTZ/ComRAT and other Turla tooling, reinforcing its role as one of the oldest publicly known malware families in Russian state-linked cyber espionage.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
At the 2015 VirusBulletin conference, a different historic gap was bridged by our own Kurt Baumgartner who revealed a solid connection between Turla and the old-school Agent.BTZ.
At the same time, malware most likely associated with the FSB penetrated U.S. defense networks to facilitate one of the most significant breaches of classified data in history (Council on Foreign Relations 2008).
ComRAT has used PowerShell to load itself every time a user logs in to the system. ComRAT can execute PowerShell scripts loaded into memory or from the file system.
32 distinct techniques documented for this family, organized by ATT&CK tactic.
'APT29 also used PowerShell to create new tasks on remote machines.'
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
The content repeatedly describes threat actors and malware using PowerShell to execute payloads, run commands, download additional malware, perform lateral movement, evade defenses, and execute scripts in memory. | Examples include: 'APT28 downloads and executes PowerShell scripts and performs PowerShell commands'; 'APT3 has used PowerShell on victim systems to download and run payloads after exploitation'; 'TA505 has used PowerShell to download and execute malware and reconnaissance scripts.'
The content repeatedly describes threat actors and malware using cmd.exe, the Windows command shell, to execute commands, launch payloads, run batch files, and automate actions on compromised hosts.
ComRAT has used PowerShell to load itself every time a user logs in to the system.
'APT29 also used PowerShell to create new tasks on remote machines.'
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
ADVSTORESHELL is capable of setting and deleting Registry values. Agent Tesla can achieve persistence by modifying Registry key entries. APT41 used a malware variant called GOODLUCK to modify the registry in order to steal credentials.
IoCs include services such as WOWmanager service, TlbControl service, WinMI32 service, HP003044 service, NetBIOS2010 service, pnppci service, ethio service, ntdos505 service.
ComRAT has used PowerShell to load itself every time a user logs in to the system.
'APT29 also used PowerShell to create new tasks on remote machines.'
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
Aria-body has the ability to inject itself into another process such as rundll32.exe and dllhost.exe... BlackEnergy injects its DLL component into svchost.exe... ComRAT has injected its orchestrator DLL into explorer.exe... Stuxnet injects an entire DLL into an existing, newly created, or preselected trusted process.
IoCs include services such as WOWmanager service, TlbControl service, WinMI32 service, HP003044 service, NetBIOS2010 service, pnppci service, ethio service, ntdos505 service.
In addition, Agent.btz and Turla use the same XOR key to encrypt their log files
Although the code itself was written from scratch and has nothing to do with WinRAR, the adversary tried to mimic WinRAR’s SFX installer. Resource data was duplicated, including icons and layouts used by the original installer
Aria-body has the ability to inject itself into another process such as rundll32.exe and dllhost.exe... BlackEnergy injects its DLL component into svchost.exe... ComRAT has injected its orchestrator DLL into explorer.exe... Stuxnet injects an entire DLL into an existing, newly created, or preselected trusted process.
The dropper then also deletes any previous installation of Agent.BTZ if it exists... Once finished, the dropper renames and self delete using the following command line
The content is a long ATT&CK-style listing of malware and threat groups that 'decrypt', 'decode', 'deobfuscate', 'unpack', or 'decompress' payloads, strings, configuration data, shellcode, and files prior to execution or use.
The content repeatedly describes malware and threat actors querying, enumerating, opening, and reading Windows Registry keys and values, e.g., "APT41 queried registry values to determine items such as configured RDP ports and network configurations" and "Reg may be used to gather details from the Windows Registry of a local or remote system at the command-line interface."
AdFind can extract subnet information from Active Directory; actors used ipconfig /all, netsh.exe, ifconfig, arp, route, nbtstat, and related APIs/commands to gather IP, MAC, DNS, DHCP, gateway, proxy, routing, ARP, and adapter information.
The content repeatedly describes malware and threat actors collecting the victim username, identifying logged-in users, running whoami, query user, quser, or similar commands to determine the current user or user sessions.
Frameworks gather information such as computer name, username, domain name, list of running processes
Frameworks gather information such as computer name, username, domain name, list of running processes, listing of files in directories, drives and network shares, as well as network configuration information
listing of files in directories, drives and network shares
The content repeatedly describes malware and threat actors collecting the current date, time, or time zone from victim systems, including examples such as "The net time command can be used... to determine the local or remote system time" and commands like "net time \\hostname" and "w32tm /tz".
While performing the analysis, we noticed that the list of files that a module named “USB Stealer” searches for on USB flash drives connected to infected computers included the names of files created by Agent.btz “mssysmgr.ocx” and “thumb.dd”.
On infected systems, the worm creates a file named ‘thumb.dd’ on all USB flash drives connected to the computer, using it to store a CAB file containing the following files: “winview.ocx”, “wmcache.nld” and “mswmpdat.tlb”. These files contain information about the infected system and the worm’s activity logs for that system.
We extracted the configuration from each sample in order to obtain the c2 address... more than seventy previously unknown live IP & DNS addresses indicating the ongoing abuse of satellite internet providers operating in both Africa & the Middle East.
106 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
103 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote access trojan mentioned in the context of COM hijacking and persistence techniques.
Referenced as a historical example of malware that crossed air gaps via USB drives rather than radio-based covert exfiltration.
Long-running Turla malware family tied to the Pentagon incident and later evolution into ComRAT; used for espionage and persistence over many years.
A sophisticated user-mode remote access trojan/backdoor attributed to Turla. The content describes a fake SFX dropper that installs a proxy DLL (activeds.dll) to load the main payload (stdole2.tlb), deletes prior installations, and communicates with numerous C2 IPs and domains.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.