njRAT, also known as Bladabindi, is a .NET-based remote-access trojan targeting Windows systems. It provides remote command-shell and desktop access, keylogging, screenshot capture, webcam access, browser credential theft, and collection of cryptocurrency-wallet information. Operators can browse, upload, download, execute, and modify files, manipulate processes and the registry, and identify remote hosts on connected networks. Some variants also support distributed denial-of-service activity.
Deployment methods include phishing and spearphishing, malicious archives exploiting WinRAR vulnerabilities CVE-2018-20250 and CVE-2023-38831, and post-exploitation delivery following Log4j exploitation. Campaigns have also bundled njRAT into fake cracked-game installers promoted through SEO poisoning, torrent sites, gaming forums, and social media. Removable-drive worms can install njRAT backdoors using deceptive shortcuts and hidden malware copies.
Observed persistence mechanisms include startup execution and registry autorun entries. Fileless deployments store encoded payloads in the registry and use PowerShell reflective loading to execute them in memory. Other deployment chains use external loaders to inject njRAT into legitimate processes through process hollowing. Analyzed variants disable or modify Windows Firewall controls to facilitate operation and command-and-control communications.
njRAT is used by both cybercriminal and espionage actors, including APT41, APT36, Blind Eagle, and TA558. Its use spans targeted organizational intrusions and consumer-focused campaigns, including attacks against Middle Eastern users, Spanish-language spearphishing operations, and malware distribution targeting gamers.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
10 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2023-38831 is a vulnerability that enables malicious actors to execute arbitrary code when a user tries to access a harmless file contained within a ZIP archive.
On March 17, 2019, QiAnXin Threat Intelligence Center captured a target attack sample against the Middle East by exploiting WinRAR vulnerability (CVE-2018-20250). When the archive gets decompressed on the vulnerable computer, the embedded njRAT backdoor (Telegram Desktop.exe) will be extracted to the startup folder.
The initial access portion of this attack began on the exchange servers in the targeted environment, when a web shell file was dropped in the public access folders in early September 2022 via ProxyShell exploitation.
The initial access portion of this attack began on the exchange servers in the targeted environment, when a web shell file was dropped in the public access folders in early September 2022 via ProxyShell exploitation.
The initial access portion of this attack began on the exchange servers in the targeted environment, when a web shell file was dropped in the public access folders in early September 2022 via ProxyShell exploitation.
As early as January 4, attackers started exploiting the CVE-2021-44228 vulnerability in internet-facing systems running VMware Horizon. Our investigation shows that successful intrusions in these campaigns led to the deployment of the NightSky ransomware. | We’ve also seen Meterpreter, Bladabindi, and HabitsRAT.
When analyzing the organization’s CVE-2017-11882 exploit document, we found that the way to bypass the shellcode length limitation is similar to that used by the APT organization TA505... Unlike most previous CVE-2017-11882 exploits, Bayworld uses malicious code in xlsx files.
Associated Analytic Story ... NjRAT
the attachment was a weaponized RTF document utilizing CVE-2012-0158 to drop an embedded, encoded portable executable (PE)... In multiple lure documents, Type: Exploit, CVE-2012-0158, Embedded Payload. | This site is likely operated by the same actor(s) that carried out the previously discussed attacks on Indian embassy officials based on shared C&C infrastructure... lure Indian military officials into becoming infected with MSIL/Crimson, njRAT, and possibly other malicious tools.
Windows Office Product Spawned Uncommon Process ... CVE-2023-21716 Word RTF Heap Corruption, CVE-2023-36884 Office and Windows HTML RCE Vulnerability ...
28 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
В их арсенале находятся такие вредоносные программы, как AgentTesla, Remcos, njRAT и другие.
APT41 and APT36 have both employed NjRAT, while APT10 has used QuasarRAT.
APT41 and APT36 have both employed NjRAT, while APT10 has used QuasarRAT.
When the archive gets decompressed on the vulnerable computer, the embedded njRAT backdoor (Telegram Desktop.exe) will be extracted to the startup folder and then triggered into execution if the victim restarts the computer or performs re-login.
From December 2, 2022 until February 2, 2023, multiple campaigns were observed deploying NjRat in its final stage.
From December 2, 2022 until February 2, 2023, multiple campaigns were observed deploying NjRat in its final stage.
33 distinct techniques documented for this family, organized by ATT&CK tactic.
892 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote-access trojan providing command-shell access, keylogging, camera and desktop surveillance, credential theft, file transfer, registry/process manipulation, screenshots, and cryptocurrency-related information theft. Observed samples created Windows Firewall rules and communicated with AWS-hosted IPs and an ngrok endpoint.
Remote-access malware represented among samples communicating with Sable Squirrel-controlled command-and-control infrastructure.
Remote-access trojan deployed by the fake GTA 6 installer. It provides remote control and surveillance capabilities, including keylogging, screenshot and webcam capture, file browsing, and browser-data theft.
A remote-access trojan deployed by the fake GTA VI installer. It provides remote control and surveillance capabilities, including keylogging, screenshot and webcam capture, file browsing, and browser-data theft.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.