Crimson RAT is a Windows-based .NET remote access trojan closely associated with Transparent Tribe, also tracked as APT36, a Pakistan-linked espionage threat actor. It has been used for years in targeted operations against Indian government, military, defense-adjacent, diplomatic, education, financial, healthcare, and space-related organizations, and has also appeared in broader lure-driven campaigns aimed at individuals of intelligence interest.
Crimson RAT is typically delivered through spearphishing and other phishing lures using malicious Office documents, macro-enabled files, PowerPoint add-ins, XLAM add-ins, ISO containers with LNK shortcuts, and archive-based droppers. Campaigns commonly rely on decoy documents themed around defense, government policy, academic material, surveys, or current events to induce execution. Transparent Tribe has also experimented with OLE embedding and packed or obfuscated variants to improve staging and evade analysis.
The malware provides full remote administration and espionage functionality. Reported capabilities include command execution, remote shell access, process enumeration and termination, file and directory traversal, file upload and download, deletion and execution of files, screenshot capture, collection of host and user information, credential theft, and exfiltration of stolen data to command-and-control infrastructure. Multiple variants support persistence, commonly through autorun mechanisms, and some samples incorporate anti-analysis delays, string obfuscation, AMSI bypass techniques, and environment checks to hinder detection and sandboxing.
Crimson RAT has evolved over time. Earlier variants exposed core RAT features, while later versions expanded command support and added stronger obfuscation and anti-analysis logic. Public reporting has described variants supporting roughly 22 commands, while others exposed larger command sets. More advanced samples have included file-splitting for exfiltration efficiency and a capability to load a USB-propagated component, indicating experimentation with removable-media-based lateral movement.
The malware is a longstanding component of Transparent Tribe’s intrusion set and remains one of the group’s best-known custom implants for long-term surveillance and data theft on compromised Windows systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Almost all C2 belongs to Contabo GmbH, a hosting provider that seems to be currently favoured by Pakistan based threat actors. Many Crimson RAT, another tool of Transparent tribe group, connect to Contabo GmbH.
2024-12-04 ⋅ Microsoft Threat Intelligence Frequent freeloader part I: Secret Blizzard compromising Storm-0156 infrastructure for espionage Crimson RAT MiniPocket TwoDash Wainscot
29 distinct techniques documented for this family, organized by ATT&CK tactic.
Remcos is primarily delivered to victims via malicious attachments in phishing emails.
It also uses Base64 encoding technique to encode the strings... The registry path is encoded in Base64 and while executing it decodes
The stage-1 HTA contains two embedded files... that are base64 encoded... Both the HTA contain embedded files...
Transparent Tribe... continuously used Crimson RAT but with either an encoded or a packed version... two new samples that were obfuscated with Eziriz’s .NET Reactor were also found
It then copies and decompresses it into the Documents folder as a screensaver file “hacrvidth vibev.scr” and executes it.
The DLL files dropped are not sideloaded by the AllaKore RAT, and they are legitimate files... These are Microsoft Windows-related libraries...
By using these commands, they can access all the files, pictures, system info, the running processes from the system.
A few of these C2 commands don’t have functionality yet, but they are similar to the ones first documented by Proofpoint.
After collecting the data from the victim’s system, it tries to make a TCP connection to send the data to the C2 server sunnyleone[.]hopto[.]org by using different customized ports each time
Opening the LNK triggers the MSHTA process, which executes a remote HTA file hosted on a compromised domain.
Almost one-third of prevalent malware families we recently analyzed support communication over non-HTTP/S protocols.
These groups are leveraging weaponized PDF documents containing malicious payloads, Microsoft Office files embedded with macro-based malware deploy RATs, Executable and Linkable Format (ELF) binaries targeting Linux systems, and advanced Mythic Command and Control (C2) frameworks for persistent network access and data exfiltration operations.
135 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
28 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote access trojan used by Transparent Tribe to infiltrate victim devices and maintain long-term command-and-control access.
Remote access trojan referenced in Secret Blizzard espionage activity and Snowblind reporting.
Remote access trojan delivered via ISO containers and LNK shortcuts in lure-based campaigns to provide remote control and data theft capability.
Remote access trojan used by Transparent Tribe/APT36 to compromise targets via ISO-delivered payloads; provides remote surveillance and control capabilities including screen monitoring, audio recording, file theft, and system control. Uses evasion such as file-size bloating with junk data and randomized function names; communicates to C2 over a custom TCP protocol on non-standard ports.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.