Crimson RAT is a Windows remote access trojan implemented in .NET and closely associated with the Pakistan-linked cyberespionage group Transparent Tribe, also known as APT36. It is used for persistent remote control, surveillance, and intelligence collection, particularly against Indian government, military, diplomatic, research, and educational targets. Its targeting also includes financial, healthcare, and space-technology organizations, as well as Indian cybersecurity and intelligence-related startups serving law-enforcement agencies.
Crimson RAT supports remote command execution, credential and sensitive-data theft, screenshot capture, audio recording, system-information collection, process enumeration and termination, and file-system reconnaissance. Operators can upload, download, execute, and delete files and deploy additional payloads. It communicates with command-and-control infrastructure using custom TCP protocols, frequently over nonstandard ports, and establishes persistence through Windows startup registry entries. Functionality varies between versions; some newer variants can load a USB-worm component to support lateral movement through removable media.
Delivery commonly involves spearphishing emails containing malicious Office documents, executable links, ZIP archives, or ISO images. Office-based chains use VBA macros, malicious add-ins, or embedded OLE objects, while ISO-based chains use deceptive Windows shortcuts and batch scripts. Decoy documents and impersonation of legitimate applications conceal payload execution. Observed evasion techniques include packing and .NET obfuscation, encoded or dynamically resolved strings, execution delays, hardware-based anti-analysis checks, and artificial binary-size inflation with junk data.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
A well-known threat actor historically associated with Pakistan, APT36 (aka Transparent Tribe), was also active. Analysts suggest it used more sophisticated malware (Crimson RAT) to target Indian infrastructure, although its relation to hacktivism is murky.
Кампания против стартапов использовала ISO-образ MeetBisht.iso с LNK-ярлыком, batch-скриптом и Crimson RAT; бинарник Crimson RAT искусственно раздут до 34 МБ мусорными данными.
2024-12-04 ⋅ Microsoft Threat Intelligence Frequent freeloader part I: Secret Blizzard compromising Storm-0156 infrastructure for espionage Crimson RAT MiniPocket TwoDash Wainscot
28 distinct techniques documented for this family, organized by ATT&CK tactic.
Process: List processes Kill process Execute commands
Batch-скрипт снимает Mark of the Web через PowerShell: Remove-Item -Stream Zone.Identifier или Unblock-File.
It also uses Base64 encoding technique to encode the strings... The registry path is encoded in Base64 and while executing it decodes
Transparent Tribe... continuously used Crimson RAT but with either an encoded or a packed version... two new samples that were obfuscated with Eziriz’s .NET Reactor were also found
It then copies and decompresses it into the Documents folder as a screensaver file “hacrvidth vibev.scr” and executes it.
The DLL files dropped are not sideloaded by the AllaKore RAT, and they are legitimate files... These are Microsoft Windows-related libraries...
By using these commands, they can access all the files, pictures, system info, the running processes from the system.
A few of these C2 commands don’t have functionality yet, but they are similar to the ones first documented by Proofpoint.
After collecting the data from the victim’s system, it tries to make a TCP connection to send the data to the C2 server sunnyleone[.]hopto[.]org by using different customized ports each time
Opening the LNK triggers the MSHTA process, which executes a remote HTA file hosted on a compromised domain.
Для Crimson RAT описана C2-связь через собственный TCP-протокол с обфусцированными командами и жёстко прописанными адресами серверов.
139 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
29 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Удалённый троян APT36, доставляемый через LNK/ISO-фишинг. Использует обфусцированный собственный TCP C2, закрепляется в системе и собирает/эксфильтрует данные.
A remote access trojan used by Transparent Tribe to infiltrate victim devices and maintain long-term command-and-control access.
Remote access trojan referenced in Secret Blizzard espionage activity and Snowblind reporting.
Remote access trojan delivered via ISO containers and LNK shortcuts in lure-based campaigns to provide remote control and data theft capability.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.