LimeRAT is a Windows-based remote access trojan written in Visual Basic .NET and commonly described as a modified variant of njRAT. It is used as a commodity RAT in multi-stage intrusion chains and has appeared in campaigns targeting government and private-sector organizations, including activity focused on Colombia and broader South America. It has also been associated with operations linked to Blind Eagle/APT-C-36/TAG-144, although attribution is not uniform across all observed LimeRAT deployments.
LimeRAT supports typical RAT functionality including remote control, file management, credential theft, keylogging, screenshot or remote desktop access, downloading additional payloads, and persistence. Reported variants and builder features also include encrypted client-server communications, plugin-based extensibility, cryptocurrency theft, DDoS capability, and optional ransomware and mining components. In observed intrusions, LimeRAT has been delivered as a final payload through script-heavy loaders that use VBScript, batch files, PowerShell, reflective loading, and process injection into legitimate Windows or .NET processes to evade detection. Persistence has been established through mechanisms including Run keys, scheduled tasks, and startup-related execution paths.
Observed delivery vectors include spearphishing and phishing emails with geopolitical, judicial, banking, invoice, or COVID-themed lures; malicious Office documents with VBA macros; compressed archives and ISO disk images; and abuse of legitimate hosting or collaboration platforms for staging additional payloads. Campaigns have used multi-stage chains in which an initial script or document selects a compatible .NET payload and then launches LimeRAT in memory or under a disguised executable name.
LimeRAT has been distributed alongside or interchangeably with other commodity RATs such as AsyncRAT, RevengeRAT, QuasarRAT, BitRAT, NanoCore RAT, Warzone RAT, and njRAT, indicating its role in flexible malware delivery ecosystems rather than a single exclusive operator toolkit. Its repeated use in Latin America-focused phishing and surveillance-oriented campaigns, especially against Colombian entities, makes it notable both as commodity malware and as a recurring component in regional threat activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Furthermore, the RAT used in this scenario was Lime-RAT, a modified version of njRAT.
In some cases, the final stage PowerShell script contained up to seven various RATs. These are typically NjRat, BitRat, Nanocore RAT, QuasarRat, LimeRat, and Warzone.
36 distinct techniques documented for this family, organized by ATT&CK tactic.
The next PowerShell script attempts to achieve persistence by creating a new Scheduled Task called "Office" that is executed immediately and then repeated every two minutes
The .rar file contains a Visual Basic Script ... to download and execute a new Powershell script
will create a Windows Script Host Shell Object to download and execute a new Powershell script by executing the following command
The next PowerShell script attempts to achieve persistence by creating a new Scheduled Task called "Office" that is executed immediately and then repeated every two minutes
The next PowerShell script attempts to achieve persistence by creating a new Scheduled Task called "Office" that is executed immediately and then repeated every two minutes
The VBS contains junk data and uses string replacement to attempt to obfuscate the executed code.
T1036 Masquerading The registered task/service pretends to be benign by name
loading them using a puppet process injection within the memory of process “C:\Windows\Microsoft.NET\Framework\v4.0.30319\cvtres.exe” ... or in “C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe”
This is accomplished by invoking aspnet_compiler.exe, injecting the final payload, and executing it.
T1071 Application Layer Protocol HTTP/DNS requests are used in the C&C traffic
this Powershell script will download a series of other different scripts which will be dropped in “C:\Users\Public\” and “C:\ProgramData\Microsoft Arts\Start\”
Remote Administration Tool For Windows ... Auto Task Force enable Windows RDP ... File manager ... Remote desktop ... Downloader Keylogger
162 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Commodity remote access trojan referenced as one of the RAT families used in Blind Eagle campaigns.
TAG-144’s Persistent Grip on South American Organizations AsyncRAT BitRAT DCRat LimeRAT NjRAT PureCrypter Quasar RAT Remcos
Remote access trojan used as a fallback payload when compatible .NET versions for AsyncRAT are not found. It communicates with the same C2 infrastructure, supports plugin-based extension, and is described as capable of screenshots, keylogging, credential/confidential data theft, botnet enrollment, network discovery, and lateral movement.
Commodity remote access trojan used by TAG-144 for remote access to victim environments.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.