LimeRAT is an open-source remote access trojan for Windows written in Visual Basic .NET. It supports remote desktop access, file management, password theft, keylogging, and downloading additional payloads. Its modular functionality also includes cryptocurrency theft, Monero mining, distributed denial-of-service attacks, screen locking, and ransomware-style encryption of files on local and removable drives. Client-server communications use AES encryption, and the malware can retrieve connection information through Pastebin. It supports persistence, USB spreading, and anti-virtual-machine behavior.
LimeRAT is distributed through phishing and spearphishing campaigns using judicial, financial, geopolitical, and COVID-themed lures. Delivery chains have included macro-enabled Excel documents, compressed archives, and ISO images containing malicious VBScript. Multistage VBScript and PowerShell loaders retrieve and decode payloads, frequently using legitimate file-hosting services. Observed deployments establish persistence through startup mechanisms, registry modifications, or scheduled tasks and execute the RAT through reflective loading or process hollowing into legitimate Windows processes. Obfuscation, in-memory execution, and attempts to disable antivirus software are recurring features of its deployment chains.
Blind Eagle, also tracked as APT-C-36 and TAG-144, has deployed LimeRAT in operations targeting Colombia and other South American organizations. LimeRAT has also appeared in spearphishing campaigns targeting government agencies in Afghanistan, India, Italy, Poland, and the United States. Multiple unrelated operators distribute it alongside other commodity RATs, including AsyncRAT and NjRAT, using shared loaders and crypter services such as HCrypt and 3LOSH.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
By the end of February was observed the use of LimeRAT, but with a very similar operation in the deployment used during the rest of the campaigns, from the first ones whose objective was the execution of NjRAT.
By the end of February was observed the use of LimeRAT, but with a very similar operation in the deployment used during the rest of the campaigns, from the first ones whose objective was the execution of NjRAT.
In some cases, the final stage PowerShell script contained up to seven various RATs. These are typically NjRat, BitRat, Nanocore RAT, QuasarRat, LimeRat, and Warzone.
36 distinct techniques documented for this family, organized by ATT&CK tactic.
The next PowerShell script attempts to achieve persistence by creating a new Scheduled Task called "Office" that is executed immediately and then repeated every two minutes
The .rar file contains a Visual Basic Script ... to download and execute a new Powershell script
will create a Windows Script Host Shell Object to download and execute a new Powershell script by executing the following command
The next PowerShell script attempts to achieve persistence by creating a new Scheduled Task called "Office" that is executed immediately and then repeated every two minutes
The next PowerShell script attempts to achieve persistence by creating a new Scheduled Task called "Office" that is executed immediately and then repeated every two minutes
The intrusion set embedded Unicode icons into Base64-encoded PowerShell strings, replaced those icons with ASCII characters at runtime, and used reversed Base64-encoded URLs and payloads.
T1036 Masquerading The registered task/service pretends to be benign by name
loading them using a puppet process injection within the memory of process “C:\Windows\Microsoft.NET\Framework\v4.0.30319\cvtres.exe” ... or in “C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe”
This is accomplished by invoking aspnet_compiler.exe, injecting the final payload, and executing it.
"The YIPPHB dropper is executed using the Installutil.exe command-line utility to start the RAT phase."
T1071 Application Layer Protocol HTTP/DNS requests are used in the C&C traffic
The loader and subsequent stages use WebClient and HTTPS/HTTP URLs to retrieve encoded payloads; the RAT connects to a configured command-and-control server.
The loader is downloaded from a TinyURL-resolved Discord CDN location; the loader subsequently downloads the YIPPHB dropper and the RAT implant from remote URLs.
Remote Administration Tool For Windows ... Auto Task Force enable Windows RDP ... File manager ... Remote desktop ... Downloader Keylogger
181 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Commodity remote access trojan referenced as one of the RAT families used in Blind Eagle campaigns.
TAG-144’s Persistent Grip on South American Organizations AsyncRAT BitRAT DCRat LimeRAT NjRAT PureCrypter Quasar RAT Remcos
Remote access trojan used as a fallback payload when compatible .NET versions for AsyncRAT are not found. It communicates with the same C2 infrastructure, supports plugin-based extension, and is described as capable of screenshots, keylogging, credential/confidential data theft, botnet enrollment, network discovery, and lateral movement.
Commodity remote access trojan used by TAG-144 for remote access to victim environments.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.