SloughRAT is a Windows Script File-based remote access trojan associated with the Iranian state-linked threat cluster commonly tracked as MuddyWater and aligned with the Canopy implant name used by CISA. It was observed in campaigns from late 2021 into early 2022 targeting organizations in the Arabian Peninsula and Jordan, with broader MuddyWater activity also affecting Turkey, Pakistan, and Armenia. Reported victim sectors included government entities, ministries, universities, and telecommunications providers, consistent with espionage-oriented targeting.
SloughRAT is implemented as obfuscated Visual Basic and JavaScript code embedded in WSF format. It supports execution of arbitrary commands delivered from command-and-control infrastructure, typically by invoking the Windows command interpreter, collecting command output, and returning results to the operator. The malware also performs basic host discovery, including collection of system identity information used to register infected hosts with its controllers. Communications were observed over HTTP, with separate registration and tasking/result workflows and randomized beacon timing to reduce predictability.
Observed delivery involved phishing messages carrying malicious Excel documents with macros. In documented infection chains, the macro dropped two WSF components: an instrumentor script and the SloughRAT payload. The instrumentor executed the next stage and established persistence by placing itself in the current user Startup folder. In some related MuddyWater intrusions, operators also used scheduled tasks, additional Visual Basic and JavaScript downloaders, and post-compromise tooling such as Ligolo for reverse tunneling.
SloughRAT is best characterized as a script-based RAT used for command execution, host registration, persistence support through its companion script, and exfiltration of command results in support of MuddyWater’s espionage and broader intrusion operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Beginning in December 2021, we observed MuddyWater using a new WSF-based RAT we named "SloughRAT" to target countries in the Arabian Peninsula.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
The obfuscated Trojan also attempts to execute arbitrary code and commands received from its command and control servers... one written in Visual Basic during 2021-2022 and one written in JavaScript in 2019-2020, which also downloads and runs arbitrary commands on the victim's system.
The maldoc consists of a malicious macro that drops two WSF files on the endpoint.
This RAT consists of obfuscated code from interweaved Visual Basic and JavaScript... one written in JavaScript in 2019-2020, which also downloads and runs arbitrary commands on the victim's system. | One of these scripts is the instrumentor script meant to execute the next stage... The second script is a WSF-based RAT we call 'SloughRAT' that can execute arbitrary commands on the infected endpoint.
MuddyWater also relies heavily on the use of DNS to contact their C2 servers, while the initial contact with the hosting servers is conducted via HTTP.
The communication with the C2 is done using the common ServerXMLHTTP from the MSXML2 API to instrument an HTTP POST request.
23 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Windows Script File-based remote access trojan used by MuddyWater. It establishes persistence via a startup-folder script and executes arbitrary commands and code received from command-and-control servers.
A WSF-based remote access trojan used by MuddyWater in phishing and espionage campaigns, enabling remote access and supporting espionage, intellectual property theft, and ransomware-linked operations.
A remote access trojan used by MuddyWater in phishing-led intrusions to gain code execution on compromised systems and run commands received from C2 servers.
A WSF-based remote access trojan used by MuddyWater that registers infected hosts with a C2 server, gathers basic host information, receives arbitrary commands, executes them via cmd.exe, and exfiltrates command output over HTTP POST.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.