Researchers across multiple reports documented continued njRAT (also known as Bladabindi) activity delivered through diverse infection chains, including malicious PowerPoint macros, phishing attachments, password-protected archives, trojanized software on Korean webhard sites, compiled AutoHotKey loaders, and typosquatted npm packages. The malware was shown using layered obfuscation in VBS and PowerShell, Base64-encoded payloads, reflective or in-memory loading, and staged retrieval from services such as paste.ee, archive.org, wtools.io, and dynamic DNS infrastructure. In one supply-chain case, the npm packages jdb.js and db-json.js installed a .NET payload that copied itself as dchps.exe and connected to 46.185.116.2:5552, while other campaigns used domains including fidapeste2.duckdns.org, xxxcarldon.duckdns.org, and 0.tcp.eu.ngrck.io for command and control.
Analysis of multiple samples showed njRAT maintaining persistence through Startup folder copies, registry Run keys, shortcuts, mutexes, firewall-rule changes, and even netsh exclusions, while some variants bundled legitimate applications so victims would not notice the infection. Once active, the RAT collected host profiling data and supported a broad set of attacker functions, including keylogging, credential theft, webcam access, screenshot and screen viewing, file transfer, process and registry manipulation, remote shell access, and full remote control of Windows systems. Reports also linked njRAT delivery to long-running loader ecosystems that rotated payload families such as Houdini, LimeRAT, RevengeRAT, AsyncRAT, and VjW0rm, underscoring the malware’s persistence as a flexible commodity RAT used across phishing, malware-hosting, and software supply-chain abuse.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
15 events from the most recent confirmed update back to the earliest known activity.
The NjRAT sample analyzed in the December 2023 write-up was first seen in October 2023. The malware copied itself to Windows and startup locations, added registry persistence, and connected to 0.tcp.eu.ngrck.io on port 18801.
The NjRAT .NET executable analyzed in the static reverse-engineering write-up was compiled on September 2, 2023. The sample later showed persistence, mutex creation, and C2 communication with 0.tcp.eu.ngrck.io:18801.
An NJRat 0.7NC sample named "utah-Robert-magazine-speaker" was first seen on 17 August 2023. The campaign delivered an obfuscated VBS file embedded in documents via phishing email.
Version 4 of the AutoHotKey campaign was first observed on May 2, 2021. It introduced directory-spamming behavior and dropped kellvbs.vbs, which led to an HCrypt variant delivering njRAT using the same C2 as an earlier VjW0rm sample.
Morphisec identified two versions of the PowerShell loader chain on April 26, 2021. The second variant added hexadecimal obfuscation to the VBScript and used the stikked.ch raw paste 5d4df3b8.
Morphisec first observed version 3 of the VjW0rm/Houdini chain on April 8, 2021. This update added VBScript to modify the Windows hosts file to block antivirus vendors and another script to kill wscript.exe traces.
A separate PowerShell-based loader chain first appeared in late April 2021. It used obfuscated VBScript and stikked.ch paste pages to stage PowerShell and C# loaders that ultimately delivered LimeRAT and RevengeRAT.
A second version of the AutoHotKey VjW0rm/Houdini chain was first observed on March 31, 2021. It added a batch script and LNK file to disable Microsoft Defender using DefenderControl.exe and a Disk Cleanup UAC bypass.
The password-protected archive Lease Agreement.zip, used to deliver a VBS-based njRAT infection chain, was first recorded by VirusTotal on 19/02/2021. The archive contained Lease Agreement.vbs, which later staged payloads from paste.ee.
Morphisec observed the first version of an AutoHotKey-based RAT delivery chain on February 17, 2021. The chain abused a conhost.exe manifest hijack to execute embedded VBScript and deliver VjW0rm and Houdini payloads.
A malicious Windows Installer sample was created and last saved on February 7, 2021, containing a CAB archive that extracted server.exe, a .NET executable identified as the primary njRAT payload. The MSI metadata indicated it was packaged with the commodity MSI Wrapper tool from exemsi.com, while an included custom-actions DLL appeared to provide generic installer functionality rather than core malware logic.
The npm security team removed the malicious typosquatting packages jdb.js and db-json.js on November 30, 2020. Sonatype had identified db-json.js as a stealthier package that depended on and invoked jdb.js.
Sonatype Intelligence flagged the typosquatting npm package jdb.js as suspicious on November 27, 2020, finding it bundled with an obfuscated installer chain that launched an njRAT dropper. Sonatype notified npm's security team the same day.
FortiGuard collected 194 malware samples communicating with hopto.org or myftp.biz between September 12 and November 16, and linked 166 of them to Bladabindi/njRAT. The activity showed continued use of dynamic DNS infrastructure for command-and-control.
ASEC reported an active njRAT distribution campaign targeting individuals in South Korea through webhard and file-sharing sites. Attackers bundled njRAT with legitimate games and utilities so the original program still ran while the victim was silently infected.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
9 references tracked. Mallory keeps watching after this page renders.
blog.morphisec.com
Open sourceinfosecwriteups.com
Open sourceinfosecwriteups.com
Open sourceforensicitguy.github.io
Open sourcecyberandramen.net
Open sourcelabs.k7computing.com
Open sourceblog.sonatype.com
Open sourceasec.ahnlab.com
Open sourceblog.fortinet.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.