ComRAT, also known historically as Agent.BTZ, is a Windows user-mode remote access trojan associated with the Turla cyberespionage group. Its lineage is linked to the 2008 compromise of U.S. military networks, including the Pentagon breach. It provides remote execution capabilities, including running PowerShell scripts and loading and executing Portable Executable payloads from memory or disk.
ComRAT uses a modular architecture with separate orchestrator and communications components. It injects its orchestrator into Windows Explorer and its communications module into the victim's default browser, making command-and-control connections appear less suspicious. ComRAT v4, identified in 2020, abuses Gmail web services for command and control. Persistence mechanisms include scheduled tasks that launch a PowerShell loader and PowerShell-based loading at user logon. The malware stores encrypted orchestrator code and loader scripts in the Windows Registry, uses machine-specific passwords to decrypt its orchestrator, and applies XOR decoding to its communications module.
Agent.BTZ variants collect the victim's username and local network configuration, including network adapter addresses, gateway details, and name-resolution and address-assignment server information. ComRAT also checks system date and time to schedule activity during weekday business hours. Historical droppers have masqueraded as WinRAR self-extracting installers and installed a proxy DLL to load the main payload after reboot.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
ESET researchers identified the ComRAT v4 backdoor in 2020 using Google Workspace web services, including Gmail, for command-and-control purposes; the activity was attributed to Turla.
At the same time, malware most likely associated with the FSB penetrated U.S. defense networks to facilitate one of the most significant breaches of classified data in history (Council on Foreign Relations 2008).
ComRAT has used PowerShell to load itself every time a user logs in to the system. ComRAT can execute PowerShell scripts loaded into memory or from the file system.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
106 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
105 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote access trojan mentioned in the context of COM hijacking and persistence techniques.
Referenced as a historical example of malware that crossed air gaps via USB drives rather than radio-based covert exfiltration.
Long-running Turla malware family tied to the Pentagon incident and later evolution into ComRAT; used for espionage and persistence over many years.
A sophisticated user-mode remote access trojan/backdoor attributed to Turla. The content describes a fake SFX dropper that installs a proxy DLL (activeds.dll) to load the main payload (stdole2.tlb), deletes prior installations, and communicates with numerous C2 IPs and domains.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.