RunningRAT

MITRE ATT&CK: S0253 View on attack.mitre.org

Aliases: RunningRAT

First seen
2018-02-01 00:00:00
Malware type
rat
Family
Malware family
Operating systems
windows
Related IoCs
31 (31 malicious)
Last IoC activity
2026-09-01 08:36:37
Profile updated
2026-07-07 15:18:48

Targeted industries: government-and-public-sector media-and-entertainment

Targeted regions: country_code:kr

Context

RunningRAT is a remote access tool that appeared in operations surrounding the 2018 Pyeongchang Winter Olympics along with Gold Dragon and Brave Prince.

Recent IoC activity

31 malicious indicators in Maltiverse are attributed to RunningRAT (S0253). The 20 most recently updated:

TypeIndicatorUpdatedSources
hostname sky.hobuff.info 2026-09-02 3
file sample 25ad9ca13dc1ee44d8c3a3d0fba9365d9e9fd65db1411a0f720dd036d11911f3 2026-08-18 2
file sample 223278e7f27613207535c392734433b4413da28fe44e43c89c2379475430f67d 2026-08-18 2
file sample 1f2e39728d627019c482b270eabb614d39100ed910797c6884fc405ae6514412 2026-08-18 2
file sample 2026-07-17_cf1ad47807fb18a7d44c83f5ef1dd053_dark-comet_darkgate_elex_gcleaner... 2026-07-18 1
file sample 2026-04-14_bab50bc000a21ef8a0f5afeed84c4f8b_elex_runningrat_wannacry_zxshell 2026-06-16 2
file sample 2026-05-23_205d8d79b80c2b18ff8433011a2ff1f0_cobalt-strike_elex_wannacry_zxshell 2026-05-23 1
file sample 2026-05-06_7b9031957cf6ab55066d8dd9eb9a64a8_elex_runningrat_wannacry_zxshell 2026-05-06 1
file sample cf6be26cbfc87fb85d345f97edd03ddc1f157c57fa3cd60da23a8cba71615842.bin 2026-04-23 1
file sample 2026-04-20_9723927e3c54655b9c66184d3dbfd00b_elex_runningrat_wannacry_zxshell 2026-04-20 1
file sample Third_stage (1).bin 2026-04-08 1
file sample bfa4248005947726368f38380aab0158.exe 2026-03-26 2
file sample server.exe 2026-03-13 1
file sample 2026-03-13_16ec005d1ec69476b53b45427a2de383_coinminer_elex_runningrat_wannacr... 2026-03-13 1
file sample db312628b3001d24ca2836ab065bed9573f65158a3b31d97f009f44110c4a4cb 2026-03-03 1
file sample 152f1bf6b11eb2f8e0f31bce6853f7f9fa604164a429741ec0973f508f6520e1 2026-03-03 1
file sample 1.exe 2026-02-17 1
file sample 2e942eab2c5befacb890b69e79044057.exe 2026-02-11 1
file sample dd9d7cf9372a5737863d4dc33f132b9a.exe 2026-02-07 1
file sample 92b81afb69efbe857c74d07e464b4097.exe 2025-10-24 1

Detection coverage

  • 1 YARA rules
  • 275 Sigma rules

Malware & tools used

  • Local Storage Discovery (attack-pattern)
  • Disable or Modify Tools (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Keylogging (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • File Deletion (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Archive Collected Data (attack-pattern)
  • Clear Windows Event Logs (attack-pattern)
  • Clipboard Data (attack-pattern)

Detection rules

  • MALPEDIA_Win_Runningrat_Auto (yara-rule)

Reports & references

  • McAfee — Gold Dragon Widens Olympics Malware Attacks Gains Permanent Presence On Victims Systems (report)
  • MITRE ATT&CK — S0253 (report)

External references