BitRAT is a commercial remote access trojan targeting Microsoft Windows, sold on underground cybercriminal forums since 2020. It provides remote desktop and hidden virtual network computing (hVNC) access, process and service management, file transfer, and execution of additional payloads. Its hVNC implementation incorporates code derived from TinyNuke. Networking features include SOCKS5 proxying, UPnP port forwarding, and reverse SOCKS4 proxying.
BitRAT supports credential theft from browsers and other applications, keylogging, clipboard monitoring, screen surveillance, webcam access, and microphone recording. It can exfiltrate stolen information, deploy XMRig for Monero mining, and conduct DDoS attacks, including Slowloris attacks. It also includes UAC bypass and Windows Defender deactivation functionality. Analyzed variants have stored captured keystrokes and clipboard data in alternate data streams. BitRAT uses encrypted configuration data and TLS-protected command-and-control communications, including self-signed certificates.
Distribution methods include phishing and spear-phishing emails, malicious Office documents, trojanized software, watering-hole attacks, fake browser updates, and unofficial Windows activation tools. Campaigns have used financial and payment-themed documents, stolen bank customer information, and NFT-themed lures. Multistage delivery chains frequently employ obfuscated scripts, PowerShell, crypters, and loaders to execute BitRAT in memory or inject it into legitimate Windows processes. Startup-folder and registry-based mechanisms have been used to maintain access.
BitRAT is used by multiple unrelated threat actors rather than a single operator. Documented users include OPERA1ER and Blind Eagle, also known as APT-C-36. Campaigns involving BitRAT have targeted African financial institutions, South American government and commercial organizations, and German automotive businesses, alongside individual Windows users.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“With help of bitrat, 888_rat, VenomRAT, BlackNET, NanoCore or common RDP OPERA1ER made fraudulent transactions and later withdrew money from ATMs.”
“After deobfuscating the executable file within the password-protected archive, we are presented with a RAT called BitRAT.”
In some cases, the final stage PowerShell script contained up to seven various RATs. These are typically NjRat, BitRat, Nanocore RAT, QuasarRat, LimeRat, and Warzone.
all of them have been associated with off-the-shelf malware like QuasarRAT, BitRat, and similar.
36 distinct techniques documented for this family, organized by ATT&CK tactic.
it decodes a command string and executes it using a WMI (Windows Management Instrumentation) object.
It then runs schtasks to create a schedule task named “calendersw” in the system “Task Scheduler“... It is also a persistence mechanism. Once it starts, back.htm adds more scheduled tasks.
2022-01-23 ⋅ forensicitguy ⋅ Tony Lambert HCrypt Injecting BitRAT using PowerShell, HTAs, and .NET
2022-01-23 ⋅ forensicitguy ⋅ Tony Lambert HCrypt Injecting BitRAT using PowerShell, HTAs, and .NET
The .inf file contains a hex encoded second stage dll payload which is decoded via certutil, written to %temp%\ and executed by rundll32.
It contains an auto-start Macro that starts using a VBA (Visual Basic Application) method called “Auto_Open()” when the Excel file is opened.
The HTML file contains a piece of JavaScript code... It creates an object, “Wscript.Shell”... In Figure 3.1 we can see it runs five command-line applications.
It then runs schtasks to create a schedule task named “calendersw” in the system “Task Scheduler“... It is also a persistence mechanism. Once it starts, back.htm adds more scheduled tasks.
“Once decrypted, the embedded payload is loaded into the current process or injected into a newly spawned WerFault.exe process.”
It then performs process hollowing to inject the malware payload into a newly-created process of “aspnet_compiler.exe”.
The downloaded file is a password-protected archive, the password for which is mentioned in the email, the email attachment, or both.
The criminals behind the campaign reportedly distribute the payloads in the guise of Windows 10 Pro license activators... The malicious file, named W10DigitalActiviation.exe, mimics a simple, one-button unofficial Windows 10 activator.
“Once decrypted, the embedded payload is loaded into the current process or injected into a newly spawned WerFault.exe process.”
It then performs process hollowing to inject the malware payload into a newly-created process of “aspnet_compiler.exe”.
After the downloader performs the operations above, it deletes itself from the infected computer in an attempt to wipe its tracks.
“After the delay, it decrypts the embedded malware payload.”
At the end of each malware code segment, the code calls the “Load()” method to load the inner .Net module... then calls the Invoke() method to invoke the “projFUD.PA.Execute()” function... with two parameters, which are an exe file’s full path and a fileless malware payload.
The malicious tool can perform a wide range of operations, including ... generic keylogging.
The malicious tool can perform a wide range of operations, including ... clipboard monitoring ...
I used the REST API to manage comments on issues and pull requests... built a GitHub-specific URL to post a comment on an issue, added a Bearer token header... | As you can see, any API service can be used as a C2 and Github is not the exception.
The configuration is decrypted to the following string, as shown in Figure 11, including a command-and-control (C&C) server and a port.
267 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
38 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote-access trojan delivered through APT-C-36 spear-phishing emails. The payload is distributed in password-protected archives reached through geographically filtered URL shorteners. Its configuration, including C2 server and port, is Camellia-encrypted; the campaign uses location and VPN filtering to evade analysis and target selected victims.
Named RAT variant in the AsyncRAT/DCRAT family lineage.
A low-volume DCRAT fork with minimal confirmed live infrastructure.
A low-cost commodity remote access trojan sold on underground forums and used via trojanized software, phishing, and watering hole attacks. It supports data exfiltration, UAC bypass, DDoS, clipboard monitoring, webcam access, credential theft, audio recording, XMRig coin mining, and keylogging.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.