Ozone RAT is a commercial Windows remote access trojan used in phishing- and spam-delivered intrusion campaigns to provide covert control of compromised systems. It has been observed in financially motivated cybercrime activity, including TA558 campaigns against hospitality and travel organizations in Latin America, and in espionage-oriented operations attributed to Sticky Werewolf targeting Russian scientific, industrial, government, and defense-related entities, as well as organizations in Belarus and Poland. German-speaking users have also been targeted through socially engineered spam lures.
Ozone RAT uses a modular architecture centered on a loader and a main DLL-based core module. The loader can establish persistence, retrieve an encrypted core module from command-and-control infrastructure, save it locally, decrypt it, and load it reflectively into memory using BTMemoryModule. Samples have been protected with Themida, and available builds have included both loader-only and fuller server variants, with optional packing. The malware is designed for stealthy remote administration and post-compromise control.
Documented capabilities include remote command execution, file, process, and service management, registry modification, payload download and execution, self-deletion, hidden VNC-based remote control, reverse proxy functionality, keylogging, screen capture, webcam access, microphone recording, and password recovery from browsers and email clients. In some campaigns, associated delivery scripts also altered browser proxy settings and installed a rogue certificate to facilitate adversary-in-the-middle phishing against web traffic before or alongside RAT deployment.
Observed delivery has relied primarily on phishing and malspam using decoy documents, spoofed government or business themes, password-protected archives, malicious attachments, and disguised executable or script files. Victims are often shown a benign-looking document while the RAT is installed in the background. Ozone RAT is best characterized as a low-cost commercial RAT that lowers the barrier to entry for operators seeking persistent remote access, surveillance, credential collection, and follow-on payload delivery on Windows hosts.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
This group continued to use a variety of malware payloads including the addition of njRAT and Ozone RAT.
При запуске в конечном итоге происходит доставка трояна удаленного доступа Ozone RAT, предназначенного для предоставления скрытого удаленного доступа к скомпрометированному устройству.
25 distinct techniques documented for this family, organized by ATT&CK tactic.
При этом для обфускации Ozone RAT Sticky Werewolf использовала протектор Themida, что затрудняло обнаружение и анализ.
По фишинговым ссылкам располагались вредоносные файлы с расширением .exe или .scr, которые были замаскированы под документы Microsoft Word или PDF.
Fig.12 Keylog from the server installed by the modified Ozone RAT client
Захват видео с экрана, доступ к веб-камере и запись звука с микрофона в режиме реального времени.
Захват видео с экрана, доступ к веб-камере и запись звука с микрофона в режиме реального времени.
Захват видео с экрана, доступ к веб-камере и запись звука с микрофона в режиме реального времени.
The malicious JavaScript begins to install a fake SSL Certificate, and sets proxies on IE, Chrome, and Mozilla browsers to a remote Proxy Auto Config (PAC) file.
17 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Модульный троян удаленного доступа, используемый через загрузчик, который скачивает с C2 зашифрованный основной DLL-модуль, сохраняет его как data.dbf, расшифровывает и загружает в память через рефлексивную DLL-загрузку. Основной модуль поддерживает управление файлами, процессами и службами, изменение реестра, кейлоггинг, захват экрана/видео/аудио, доступ к веб-камере, удаленное выполнение команд, загрузку и запуск файлов, самоудаление, HVNC, восстановление паролей из браузеров и почтовых клиентов, а также режим обратного прокси.
Remote access trojan delivered via a password-protected archive in a phishing campaign, providing covert remote access to the compromised device.
Remote access trojan observed as part of TA558's malware set in 2020.
Commercialized remote access trojan used in a spam-delivered infection chain. In this campaign it is downloaded after a malicious JavaScript sets browser proxies and installs a fake SSL certificate for man-in-the-middle activity. Ozone supports file operations, remote desktop control, keylogging, and hidden VNC (hVNC), and can be deployed as a loader-only or FAT server variant with a core DLL loaded via reflective DLL injection.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.