BitRAT is a commercial off-the-shelf Windows remote access trojan sold on underground criminal forums since 2020–2021 and widely used in commodity intrusion campaigns. It is commonly delivered through phishing and malspam, trojanized or cracked software, fake browser updates, watering-hole and drive-by activity, and lures such as unofficial Windows activators, payment documents, NFT-themed files, and other socially engineered attachments. BitRAT has also appeared as a payload embedded in loaders and crypters including BLISTER, DelphiCrypter, HCrypt, and APOMacroSploit-driven infection chains.
BitRAT provides broad post-compromise control over infected systems. Reported capabilities include remote command execution and system management, credential theft, keylogging, clipboard monitoring, webcam and microphone access, data exfiltration, hidden desktop or HVNC-style remote control, proxying, cryptocurrency mining, DDoS functionality, UAC bypass, and Windows Defender evasion or deactivation. Multiple analyses also describe persistence via startup mechanisms or scheduled tasks, reflective or in-memory loading, and process injection or hollowing into legitimate Windows processes to reduce detection.
The malware is strongly associated with Windows environments and has been observed in campaigns targeting a wide range of victims, including South American organizations, German automotive-sector entities, financial-sector targets, NFT enthusiasts, and users seeking pirated software activation. It has been linked in public reporting to activity by commodity cybercrime operators and has been used alongside other malware families such as AveMariaRAT, PandoraHVNC, QuasarRAT, NanoCore, XWorm, AZORult, Raccoon, and Cobalt Strike. BitRAT has also been noted for reuse of code or functionality associated with TinyNuke, particularly around HVNC-related features.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
According to Bitdefender, BitRAT is a notorious remote access trojan (RAT) marketed on underground cybercriminal web markets and forums.
In some cases, the final stage PowerShell script contained up to seven various RATs. These are typically NjRat, BitRat, Nanocore RAT, QuasarRat, LimeRat, and Warzone.
all of them have been associated with off-the-shelf malware like QuasarRAT, BitRat, and similar.
36 distinct techniques documented for this family, organized by ATT&CK tactic.
it decodes a command string and executes it using a WMI (Windows Management Instrumentation) object.
It then runs schtasks to create a schedule task named “calendersw” in the system “Task Scheduler“... It is also a persistence mechanism. Once it starts, back.htm adds more scheduled tasks.
2022-01-23 ⋅ forensicitguy ⋅ Tony Lambert HCrypt Injecting BitRAT using PowerShell, HTAs, and .NET
2022-01-23 ⋅ forensicitguy ⋅ Tony Lambert HCrypt Injecting BitRAT using PowerShell, HTAs, and .NET
The .inf file contains a hex encoded second stage dll payload which is decoded via certutil, written to %temp%\ and executed by rundll32.
It contains an auto-start Macro that starts using a VBA (Visual Basic Application) method called “Auto_Open()” when the Excel file is opened.
The HTML file contains a piece of JavaScript code... It creates an object, “Wscript.Shell”... In Figure 3.1 we can see it runs five command-line applications.
It then runs schtasks to create a schedule task named “calendersw” in the system “Task Scheduler“... It is also a persistence mechanism. Once it starts, back.htm adds more scheduled tasks.
The final stage PowerShell is responsible for deobfuscating and injecting the payload (RATs) into the given process.
It then performs process hollowing to inject the malware payload into a newly-created process of “aspnet_compiler.exe”.
The loaded executables are obfuscated with various techniques.
The criminals behind the campaign reportedly distribute the payloads in the guise of Windows 10 Pro license activators... The malicious file, named W10DigitalActiviation.exe, mimics a simple, one-button unofficial Windows 10 activator.
The final stage PowerShell is responsible for deobfuscating and injecting the payload (RATs) into the given process.
It then performs process hollowing to inject the malware payload into a newly-created process of “aspnet_compiler.exe”.
After the downloader performs the operations above, it deletes itself from the infected computer in an attempt to wipe its tracks.
The payload is first decoded using the function ArgCount [GZip decompress] After decoded the assembly will be loaded by the Assembly.Load() method
At the end of each malware code segment, the code calls the “Load()” method to load the inner .Net module... then calls the Invoke() method to invoke the “projFUD.PA.Execute()” function... with two parameters, which are an exe file’s full path and a fileless malware payload.
2022-01-23 ⋅ forensicitguy ⋅ Tony Lambert HCrypt Injecting BitRAT using PowerShell, HTAs, and .NET
The malicious tool can perform a wide range of operations, including ... generic keylogging.
The malicious tool can perform a wide range of operations, including ... clipboard monitoring ...
I used the REST API to manage comments on issues and pull requests... built a GitHub-specific URL to post a comment on an issue, added a Bearer token header... | As you can see, any API service can be used as a C2 and Github is not the exception.
267 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
34 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named RAT variant in the AsyncRAT/DCRAT family lineage.
A low-volume DCRAT fork with minimal confirmed live infrastructure.
A low-cost commodity remote access trojan sold on underground forums and used via trojanized software, phishing, and watering hole attacks. It supports data exfiltration, UAC bypass, DDoS, clipboard monitoring, webcam access, credential theft, audio recording, XMRig coin mining, and keylogging.
Windows remote access trojan promoted as an advanced, fully activated RAT.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.