Researchers identified two active remote access trojan operations built on commodity malware families, with one involving a customized QuasarRAT variant dubbed DollRAT or "Lilly's RAT V8" and the other using njRAT v0.7d (Bladabindi). DollRAT was observed using a modified QuasarRAT v1.4.1 codebase with ConfuserEx obfuscation, runtime string decryption, and command-and-control traffic routed through an ngrok TCP tunnel at 0.tcp.eu.ngrok.io:18107, backed by AWS infrastructure in Frankfurt. The malware supports credential theft from browsers and FTP clients, keylogging with HTML-formatted logs, system reconnaissance, remote shell access, file management, remote desktop, registry changes, reverse proxying, and persistence through Run keys and scheduled tasks. Embedded branding including "Lilly's RAT V8" and "C.U.M Software Inc." suggests an actively maintained custom build rather than an unmodified public RAT.
A separate analysis tracked an njRAT sample named Client.exe to a broader campaign using the hardcoded No-IP hostname njspider.myddns.me on TCP port 4444, resolving to Belgian residential IP 62.235.6.231. That operation has reportedly been active since at least late 2025, with multiple related binaries and rapid rebuilds sharing the same infrastructure. The njRAT sample retained standard capabilities including persistence via HKCU Run keys, keylogging, screenshots, webcam capture, remote shell, file transfer, plugin execution, USB spreading, and plaintext TCP beaconing. Across both cases, operators relied on legitimate services such as ngrok, No-IP, ipwho.is, and api.ipify.org to mask or support C2 activity, while the tooling and infrastructure pointed to low-sophistication but active commodity malware operations.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Breakglass first observed DollRAT on 2026-03-14 and assessed it as a newly seen custom QuasarRAT v1.4.1 variant branded as "Lilly's RAT V8." The malware used ConfuserEx obfuscation, runtime string decryption, and an active ngrok TCP tunnel for command-and-control.
The analyzed njRAT sample was observed on VirusTotal about three minutes after compilation, suggesting active distribution or testing on 2026-03-12. The sample resolved its C2 hostname to Belgian residential Proximus IP 62.235.6.231.
On 2026-03-12, the operator rapidly rebuilt multiple njRAT samples tied to the same No-IP DDNS infrastructure. One analyzed VB.NET sample, Client.exe, was compiled that day and configured to use njspider.myddns.me over TCP port 4444.
A broader njRAT v0.7d (Bladabindi) campaign using the hostname njspider.myddns.me was active since at least December 2025. Breakglass linked at least eight binaries to the same infrastructure, indicating an ongoing commodity RAT operation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
intel.breakglass.tech
Open sourceintel.breakglass.tech
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.