Warzone RAT, also known as Ave Maria, is a Windows remote access trojan distributed through a malware-as-a-service model. It provides remote desktop control through RDP and hidden VNC, webcam capture, live and offline keylogging, and password theft from multiple web browsers and the Outlook and Thunderbird email clients. It communicates with command-and-control infrastructure over TCP and can use PowerShell to download files and execute commands.
Warzone RAT supports privilege escalation through malicious DLL injection and Windows User Account Control bypasses, including Control Panel execution hijacking and elevated IFileOperation abuse. Its deployment chains have used malicious Office documents, JavaScript, and PowerShell, with process injection and process hollowing to conceal payload execution. Observed infection chains establish persistence through startup-folder execution and scheduled tasks. Hidden VNC enables interactive access with reduced visibility to the victim.
Distribution includes phishing and malicious spam, with COVID-19-themed documents exploiting CVE-2017-11882, Ukraine-related donation lures, and delivery-notification or invoice messages linking to payloads hosted on legitimate cloud services. DBatLoader and PrivateLoader have also delivered Warzone RAT. The malware has been used by APT-C-36, also known as Blind Eagle, an actor targeting organizations in Colombia and elsewhere in South America.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The malicious spam messages were crafted to exploit CVE-2017-11882. The remote code execution flaw is specific to Microsoft Word Equation Editor. Once exploited, the Warzone RAT payload is downloaded and installed. | From May 21st onward, we observed multiple COVID-themed spam campaigns distributing the Warzone RAT. The malicious spam messages were crafted to exploit CVE-2017-11882.
Associated Analytic Story AgentTesla CVE-2023-21716 Word RTF Heap Corruption Compromised Windows Host FIN7 PlugX Warzone RAT
6 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“In the past, we have observed that APT-C-36 makes use of RATs such as: ... Warzone RAT ...”
Cisco Talos recently discovered a malicious campaign targeting government employees and military personnel in the Indian sub-continent with two commercial and commodity RAT families known as NetwireRAT (aka NetwireRC) and WarzoneRAT (aka Ave Maria).
In some cases, the final stage PowerShell script contained up to seven various RATs. These are typically NjRat, BitRat, Nanocore RAT, QuasarRat, LimeRat, and Warzone.
To give an overview, here is a list of all observed tools and malware types the actor has been using in recent years: Warzone RAT / AveMaria RAT
Apart from the above legitimate tools used for malicious purposes, Scattered Spider also conducts phishing attacks to install malware like the WarZone RAT, Raccoon Stealer, and Vidar Stealer, to steal from compromised systems login credentials, cookies, and other data useful in the attack.
For remote access, YoroTrooper has also deployed commodity malware, such as AveMaria/Warzone RAT, LodaRAT and Meterpreter.
30 distinct techniques documented for this family, organized by ATT&CK tactic.
Adversaries may use a non-application layer protocol for communication between host and C2 server or among infected hosts within a network. Specific examples include use of network layer protocols, such as the Internet Control Message Protocol (ICMP), transport layer protocols, such as the User Datagram Protocol (UDP), session layer protocols, such as Socket Secure (SOCKS), as well as redirected/tunneled protocols, such as Serial over LAN (SOL).
470 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
152 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote-access trojan previously used by APT-C-36.
Remote access trojan delivered via COVID-themed spam exploiting Microsoft Word Equation Editor RCE.
A remote access trojan associated here with process injection, keylogging-related calls, and command-and-control traffic.
Phishing Campaign Delivering Three Fileless Malware: AveMariaRAT / BitRAT / PandoraHVNC – Part I
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.