Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
KermitRAT is an advanced Remote Access Trojan (RAT) detected in 2026 ... used in targeted phishing campaigns targeting industrial organizations operating primarily in Russia and Belarus.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
KermitRAT.ps1 ... PowerShell Execution ... The PowerShell-based malware initially uses the SilentlyContinue setting.
The MITRE ATT&CK matrix lists Windows Command Shell (T1059.003) under Execution.
Local IP addresses are collected using the Get-NetIPAddress command, while the external IP address is queried through online services. Subsequently, Get-NetTCPConnection is used to enumerate active TCP connections.
Get-NetTCPConnection is used to enumerate active TCP connections and the processes associated with them ... processes with the highest CPU usage [are examined].
The malware performs detailed system discovery ... collecting information related to hardware, the operating system, network configuration, and security components.
The root directory of each drive is then scanned ... the remaining top-level directories are listed.
Only newly created or modified files are added to the synchronization list ... compressed, and transferred to the C2 infrastructure.
Real-time keystrokes are captured through GetAsyncKeyState API calls ... virtual key codes are continuously iterated over to capture all pressed keys.
When the screen command is received, a screenshot is captured using .NET Drawing.Bitmap and the CopyFromScreen APIs and temporarily saved in PNG format.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.