Researchers reported multiple BitRAT distribution campaigns that used highly tailored social-engineering lures to infect Windows users with the commodity remote access trojan. In one campaign, attackers abused a Colombian cooperative bank’s compromised infrastructure and reused stolen customer records in malicious Excel files, indicating a real breach involving roughly 418,777 rows of sensitive data. Qualys said the operators likely exploited SQL injection with sqlmap, then used obfuscated macros, certutil, and rundll32 to stage and launch BitRAT from payloads hosted on a throwaway GitHub repository. Separate reporting showed BitRAT also spread through fake Windows 10 activators shared on South Korean webhards, Discord, and social media, where a bogus activation tool downloaded the malware and attempted to weaken Windows Defender protections.
Fortinet documented another BitRAT campaign that targeted NFT enthusiasts, using Hebrew-language Excel lures and Discord-hosted payloads to deliver the malware through batch scripts, PowerShell, and DLL injection into a copied MSBuild.exe process. Across the campaigns, BitRAT was described as a low-cost malware-as-a-service tool sold on underground forums since 2021, with capabilities including credential theft, keylogging, webcam and microphone access, hidden remote desktop (HVNC), file exfiltration, cryptocurrency mining, DDoS activity, and persistence via startup-folder placement or process injection. The reporting highlights how BitRAT operators increasingly combine stolen data, topical themes, and pirated software bait with legitimate services such as GitHub and Discord to improve infection success.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
13 events from the most recent confirmed update back to the earliest known activity.
Qualys Threat Research Unit published an analysis of a BitRAT campaign that used malicious Excel lures containing stolen data from a Colombian cooperative bank, revealing both the malware delivery chain and the underlying bank data breach.
FortiGuard Labs published its analysis of the NFT-themed BitRAT campaign, detailing the Excel macro lure, Discord-based staging, persistence, and BitRAT capabilities.
The malicious Excel macro file used in the NFT-themed BitRAT campaign was uploaded to a public online scan service on January 3, 2022.
Fortinet says the DLL used in the NFT-themed BitRAT infection chain appeared to have been compiled on January 2, 2022.
Bitdefender published research on a BitRAT campaign targeting users seeking pirated Windows activation, attributing it to suspected Korean threat actors based on distribution patterns and Korean-language code artifacts.
Qualys reports that BitRAT had been sold on underground forums since February 2021 as a low-cost commercial remote access trojan.
Malpedia lists a string-based YARA rule named win_bit_rat_w0 for BitRAT dated 2020-08-28 and attributed to KrabsOnSecurity. The rule used strings including TaskbarGlomLevel, profiles.ini, RtlCreateUserThread, nss3.dll, and AVE_MARIA to detect BitRAT payloads.
Fortinet's report states that BitRAT was first sold on a hacking forum in August 2020, marking the malware's initial appearance on the underground market.
FortiGuard Labs discovered a campaign using malicious Excel macro files named NFT_Items.xlsm or NFT_LIST.xlsm to infect likely Israel-based NFT enthusiasts with BitRAT. The infection chain used a batch file, PowerShell, Discord-hosted payloads, and DLL injection into a copied MSBuild.exe process.
The attackers reused stolen customer data from the Colombian cooperative bank in malicious Excel lure documents to make the files appear legitimate and improve infection success.
Qualys found evidence that an adversary hijacked the infrastructure of a Colombian cooperative bank, used sqlmap to identify SQL injection weaknesses, and obtained database dumps containing 418,777 rows of sensitive customer data.
Qualys found that the GitHub repository used to host BitRAT payloads in the bank-themed campaign was created in mid-November and appeared to be a throwaway account.
A BitRAT campaign distributed malware disguised as an unofficial Windows 10 Pro activator through South Korean webhards, with links shared on Discord and social media. The downloader installed BitRAT as Software_Reporter_Tool.exe, added Windows Defender exclusions, and deleted itself.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
malpedia.caad.fkie.fraunhofer.de
Open sourceblog.qualys.com
Open sourceasec.ahnlab.com
Open sourcefortinet.com
Open sourcebitdefender.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.