CrimsonRAT is a Windows .NET remote access trojan closely associated with Transparent Tribe, also tracked as APT36 and Mythic Leopard. It has been observed since at least 2020 as one of the group’s primary implants for establishing long-term access in espionage operations. Activity involving CrimsonRAT has been linked to campaigns targeting Indian government, defense, military, diplomatic, and educational entities, as well as government-related organizations in Southeast Asia.
CrimsonRAT is typically delivered through spearphishing campaigns using malicious Office documents with VBA macros, including Word and Excel lures, and has also been distributed through trojanized software installers and counterfeit websites impersonating legitimate Indian government services such as Kavach. In document-based intrusions, macros commonly extract or download the next-stage payload and execute it on Windows systems.
The malware provides broad remote administration and surveillance functionality. Reported capabilities include browser credential theft, keylogging, screenshot capture, process enumeration, directory and drive listing, file read, write, and deletion, arbitrary command execution, exfiltration to command-and-control infrastructure, and retrieval or download-and-execution of additional payloads. Some reporting also notes support for auxiliary modules, including keylogger- and USB-related components, indicating continued evolution of the toolset.
CrimsonRAT is widely regarded as a signature Transparent Tribe implant rather than a commodity family. Its repeated use across multiple campaigns, overlap with related Transparent Tribe tooling such as ObliqueRAT, and consistent targeting patterns make it a high-confidence malware family for tracking that actor’s Windows espionage operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
For example, if the final payload was a CrimsonRAT or ObliqueRAT sample, we would attribute the VBA code to the Transparent Tribe group.
domain names similar to file-sharing services are used to trick the general audience into downloading malicious XLS files with macros that download malware samples of CrimsonRAT, ObliqueRAT, and Poseidon families.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
The distribution of the fake Kavach installers is done via counterfeit websites that are clones of legitimate sites of Indian governments.
Their initial infection vector is usually email, purporting to come from official sources and containing a lure, which can be a Word document or more often, an Excel spreadsheet.
CrimsonRAT is the primary spearhead tool of APT36, able to steal credentials from the browser, list running processes...
The sendData method is responsible for constructing the data collected by other methods and classes and sending it to the C2. The mRun method constructs the socket and sends the data to the C2 server using the variables specified in the Settings class.
mRun performs a connectivity check to decide whether to connect to the C2 using the hostname shareboxs[.]net or the hardcoded IP address 173[.]249[.]50[.]243 .
14 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote access trojan deployed by APT36 via sophisticated phishing attacks.
A Windows RAT used by APT36 in parallel with its Linux malware development and delivered through lure documents such as xlam, ppam, and docm files.
Windows remote access trojan associated with Transparent Tribe, referenced for shared versioning conventions and overlapping C2 infrastructure indicators.
A RAT associated in the report with Transparent Tribe infrastructure; specifically mentioned as sharing C2-linked IP infrastructure with CapraRAT activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.