RATANKBA is a Lazarus-linked Windows malware family used in financially motivated intrusion activity, including watering-hole compromises against banks and financial institutions and later cryptocurrency-focused campaigns. It has been observed both as a PE-based implant and in PowerShell-based variants commonly referred to as PowerRatankba. Across reporting, RATANKBA has functioned primarily as an early-stage reconnaissance and staging implant that profiles infected hosts, communicates with command-and-control infrastructure, and can retrieve or launch additional payloads; some reporting also characterizes campaign samples as Downloader.Ratankba. Lazarus has also used related Ratankba malware in operations targeting point-of-sale businesses.
RATANKBA performs host reconnaissance by enumerating running processes, collecting network configuration details, querying the current user and logged-on sessions, and reading proxy-related Registry settings. Documented behaviors include use of commands such as whoami, query user, ipconfig /all, and net view, as well as WMI-based process monitoring. Some variants support downloading and executing follow-on payloads, while others can perform reflective DLL injection into a specified process, indicating use as a post-compromise loader and execution component. In cryptocurrency-themed campaigns, PowerRatankba was used to identify potentially valuable victims before delivering a custom remote-access payload to selected systems.
Observed delivery methods include compromised legitimate websites used as watering holes against preselected financial-sector targets, as well as spearphishing and lure-based distribution in cryptocurrency campaigns using malicious shortcut files, compiled HTML help files, JavaScript downloaders, macro-enabled Office documents, and trojanized cryptocurrency applications. The malware family is associated with Lazarus Group and aligns with that actor’s broader pattern of combining reconnaissance, staged payload delivery, and financially motivated targeting across banking, payment, and cryptocurrency environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Several watering hole attacks targeting the banking and financial industries that occurred at the end of 2016 and beginning of 2017 utilized a first stage downloader implant dubbed Ratankba.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes threat actors and malware using WMI/WMIC/wmiexec for remote execution, lateral movement, discovery, persistence, and administrative actions; e.g., 'APT41 used WMI in several ways, including for execution of commands via WMIEXEC as well as for persistence via PowerSploit' and 'Scattered Spider used Windows Management Instrumentation (WMI) to move laterally via Impacket.'
The content repeatedly describes threat actors and malware using PowerShell to execute payloads, run commands, download additional malware, perform lateral movement, evade defenses, and execute scripts in memory. | Examples include: 'APT28 downloads and executes PowerShell scripts and performs PowerShell commands'; 'APT3 has used PowerShell on victim systems to download and run payloads after exploitation'; 'TA505 has used PowerShell to download and execute malware and reconnaissance scripts.'
Aria-body has the ability to inject itself into another process such as rundll32.exe and dllhost.exe... BlackEnergy injects its DLL component into svchost.exe... ComRAT has injected its orchestrator DLL into explorer.exe... Stuxnet injects an entire DLL into an existing, newly created, or preselected trusted process.
Aria-body has the ability to inject itself into another process such as rundll32.exe and dllhost.exe... BlackEnergy injects its DLL component into svchost.exe... ComRAT has injected its orchestrator DLL into explorer.exe... Stuxnet injects an entire DLL into an existing, newly created, or preselected trusted process.
Cobalt Strike has the ability to load DLLs via reflective injection... Lazarus Group malware sample performs reflective DLL injection... Matryoshka uses reflective DLL injection... Netwalker DLL has been injected reflectively into the memory of a legitimate running process.
The content repeatedly describes malware and threat actors querying, enumerating, opening, and reading Windows Registry keys and values, e.g., "APT41 queried registry values to determine items such as configured RDP ports and network configurations" and "Reg may be used to gather details from the Windows Registry of a local or remote system at the command-line interface."
AdFind can extract subnet information from Active Directory; actors used ipconfig /all after exploiting a machine; numerous malware and groups used ipconfig, ifconfig, arp, route, netsh, nbtstat, NBTscan, and related APIs to gather IP, MAC, DNS, DHCP, gateway, proxy, domain, ARP cache, routing, and adapter details.
During the 2015 Ukraine Electric Power Attack, Sandworm Team remotely discovered systems over LAN connections. OT systems were visible from the IT network as well, giving adversaries the ability to discover operational assets.
The content repeatedly describes malware and threat actors collecting the username, identifying the current user, enumerating logged-on users, or running commands such as whoami, query user, and quser to determine user context on compromised systems.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, sw_vers -productVersion, and fsutil.
“actors used the following commands… to enumerate user accounts: net user >> %temp%\download; net user /domain >> %temp%\download … APT1 used the commands net localgroup, net user, and net group to find accounts… APT32 enumerated administrative users using the commands net localgroup administrators … OilRig has run net user, net user /domain, net group "domain admins" /domain …”
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
45 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor that runs whoami and query user for user discovery.
Malware with a PowerShell-script variant replacing the traditional PE form.
Gathers victim IP addresses via ipconfig -all.
Malware that performs reflective DLL injection into a specified process ID.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.