STRRAT, also known as Strigoi Master, is a Java-based remote access trojan observed since at least mid-2020. It is Windows-focused despite its Java implementation, and some distribution packages bundle or install a Java Runtime Environment so the final payload can execute without Java having been previously installed.
STRRAT executes commands received from command-and-control servers and supports remote shell and PowerShell execution, remote screen control, file transfer and management, process enumeration and termination, reverse proxying, and downloading and executing additional payloads. It steals credentials from browsers and email clients, including Chrome, Firefox, Microsoft Edge, Internet Explorer, Outlook, Thunderbird, and Foxmail. Its keylogging functionality records keystrokes and active window titles, with both offline logging and immediate exfiltration modes. It gathers host and security-software information, attempts privilege elevation, and can install RDPWrap or Hidden RDP components to enable remote desktop access. Persistence mechanisms include scheduled tasks, Windows startup execution, and registry autoruns.
STRRAT includes extortion functionality whose implementation varies between versions: early variants merely rename files to simulate encryption, while analyzed later variants implement AES-based file encryption and decryption. Operators can display attacker-supplied ransom messages. Evasion measures include Java obfuscation, encrypted configuration data, and distribution in polyglot files combining a signed Windows installer with an appended malicious Java archive.
Distribution commonly uses phishing and malicious spam with shipping, orders, payment, and other business-themed lures. Delivery chains include archived Java attachments, macro-enabled Office documents, Java downloaders, and intermediary malware such as RATDispenser and Vjw0rm. Payloads have also been hosted on public services including AWS and GitHub. STRRAT has been used by TA2541, whose campaigns target aviation, aerospace, transportation, manufacturing, and defense organizations, and historically by Bloody Wolf, also tracked as Stan Ghouls. Italian-language malspam campaigns have continued distributing the family into 2026.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In recent campaigns, vjw0rm and STRRAT also leveraged task creation and adding entries to the registry.
Historically, the group’s weapon of choice was the remote access Trojan (RAT) STRRAT, also known as Strigoi Master.
32 distinct techniques documented for this family, organized by ATT&CK tactic.
The malware establishes persistence by creating a scheduled task called “Skype”.
STRRAT is a multi-capability Remote Access Trojan... Unusually, it is Java-based
Run method: CMD.EXE /C C:\User\bin\java.exe -jar C:\User\x.jar
The malware establishes persistence by creating a scheduled task called “Skype”.
creates a new entry under the “Software\Microsoft\Windows\CurrentVersion\Run” registry key ... prevents the display of the last username by modifying a Registry value.
The malware establishes persistence by creating a scheduled task called “Skype”.
In addition, despite other classes being obfuscated, there are deobfuscated classes referring to Windows USER32, WinGDI, Kernel32, and HBrowserNativeApis keywords.
As Figure 1 shows, this sample is clearly not from Maersk Shipping. The threat actors are hoping that recipients do not look too closely.
perform keylogger activities ... implements the addKeyListener function, which listens to keyPressed and keyReleased events ... The window name on which the keys were pressed is also recorded.
It retrieves the content of the “COMPUTERNAME” (or “HOSTNAME”) and “USERNAME” environment variables that will be exfiltrated.
processes command — The RAT retrieves a list of running processes via a WMI query, which will be exfiltrated to the C2 server.
perform keylogger activities ... implements the addKeyListener function, which listens to keyPressed and keyReleased events ... The window name on which the keys were pressed is also recorded.
During this infection, STRRAT was installed... The following traffic occured on an infected Windows host: 54.202.26[.]55 port 80 ... port 443 ... 105.109.211[.]84 port 1990 ... TCP traffic generated by STRRAT
rev-proxy command — This command implements a reverse proxy on the host. It receives a “CONNECT IP:Port” request and sends back a “200 Connection Established” message.
45 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
23 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A trojan distributed using a polyglot combining a signed Windows MSI installer with malicious Java JAR code appended to its end. The content does not describe its post-infection capabilities.
Remote access trojan previously used by the Stan Ghouls/Bloody Wolf group in targeted campaigns.
Remote access trojan previously used by the actor prior to shifting to NetSupport RAT.
Remote access trojan historically used by the Stan Ghouls/Bloody Wolf group to maintain control of infected systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.