WarzoneRAT
MITRE ATT&CK: S0670 View on attack.mitre.org
Aliases: Warzone, Ave Maria, AVE_MARIA, AveMariaRAT, Warzone RAT, WarzoneRAT, avemaria
- First seen
- 2018-10-01 00:00:00
- Malware type
- rat, credential-stealer
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 1869 (1572 malicious)
- Last IoC activity
- 2026-09-02 02:41:20
- Profile updated
- 2026-07-07 12:38:40
Targeted industries: financial-services government-and-public-sector healthcare-and-pharmaceutical retail-and-hospitality technology-and-telecommunications
Context
WarzoneRAT is a malware-as-a-service remote access tool (RAT) written in C++ that has been publicly available for purchase since at least late 2018.
Recent IoC activity
1,576 malicious indicators in Maltiverse are attributed to WarzoneRAT (S0670). The 20 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| IP address | 213.152.187.195 | 2026-09-03 | 8 |
| IP address | 3.126.224.214 | 2026-09-03 | 4 |
| hostname | l34d3r.duckdns.org | 2026-09-03 | 1 |
| hostname | nan.ydns.eu | 2026-09-03 | 1 |
| hostname | dfdgdsasedw.ydns.eu | 2026-09-03 | 1 |
| hostname | pubg.ddns.net | 2026-09-03 | 1 |
| hostname | huhuhu.ooguy.com | 2026-09-03 | 2 |
| hostname | newnex.3utilities.com | 2026-09-03 | 2 |
| hostname | goalblistr.ydns.eu | 2026-09-03 | 1 |
| hostname | andronmatskiv20.sytes.net | 2026-09-03 | 1 |
| hostname | respainc.duckdns.org | 2026-09-03 | 1 |
| hostname | msteelwar.ddns.net | 2026-09-03 | 1 |
| hostname | yulanda.hopto.org | 2026-09-03 | 1 |
| hostname | warzonlogs.duckdns.org | 2026-09-03 | 1 |
| hostname | asdfwrkhl.warzonedns.com | 2026-09-03 | 1 |
| hostname | urchy.duckdns.org | 2026-09-03 | 1 |
| hostname | rex1010.duckdns.org | 2026-09-03 | 2 |
| hostname | ccnewcdt.duckdns.org | 2026-09-03 | 2 |
| hostname | wz-patient001.duckdns.org | 2026-09-03 | 1 |
| hostname | group.loseyourip.com | 2026-09-03 | 1 |
Detection coverage
- 2 YARA rules
- 844 Sigma rules
Malware & tools used
- Process Discovery (attack-pattern)
- Keylogging (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- Malicious File (attack-pattern)
- Disable or Modify Tools (attack-pattern)
- Exfiltration Over C2 Channel (attack-pattern)
- Credentials from Web Browsers (attack-pattern)
- Bypass User Account Control (attack-pattern)
- Data from Local System (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- System Information Discovery (attack-pattern)
- Proxy (attack-pattern)
- Symmetric Cryptography (attack-pattern)
- Remote Desktop Protocol (attack-pattern)
- Modify Registry (attack-pattern)
- Component Object Model Hijacking (attack-pattern)
- Hide Artifacts (attack-pattern)
- Spearphishing Attachment (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- PowerShell (attack-pattern)
- Native API (attack-pattern)
- Video Capture (attack-pattern)
- Hidden Window (attack-pattern)
- Process Injection (attack-pattern)
- Windows Command Shell (attack-pattern)
Used by threat actors
- Scattered Spider (threat-actor)
- TA2541 (threat-actor)
- Confucius (threat-actor)
Detection rules
- DITEKSHEN_MALWARE_Win_Warzonerat (yara-rule)
- MALPEDIA_Win_Ave_Maria_Auto (yara-rule)
Reports & references
- pwc.co.uk — Pwc Cyber Threats 2020 A Year In Retrospect (report)
- Kaspersky — 90703 (report)
- kaspersky.com — 2019 Fin7 Hacking Group Targets More Than 130 Companies After Leaders Arrest (report)
- Cisco Talos — Attributing Yorotrooper (report)
- Kaspersky — 109552 (report)
- CISA — Aa23 320A (report)
- uptycs.com — Confucius Apt Deploys Warzone Rat (report)
- blogs.blackberry.com — Dot Net Stubs Sowing The Seeds Of Discord (report)
- info.spamhaus.com — 2022%20Q3%20Botnet%20Threat%20Update (report)
- info.spamhaus.com — 2023%20Q3%20Botnet%20Threat%20Update (report)
- info.spamhaus.com — 2023%20Q1%20Botnet%20Threat%20Update (report)
- info.spamhaus.com — 2023%20Q2%20Botnet%20Threat%20Update (report)
- Cisco Talos — 2020 Year In Malware (report)
- CISA — Aa23 320A Scattered Spider (report)
- Kaspersky — 99204 (report)
- spamhaus.org — 2020 Q2 Spamhaus Botnet Threat Report (report)
- ciphertechsolutions.com — Roboski Global Recovery Automation (report)
- securityintelligence.com — Roboski Global Recovery Automation (report)
- cocomelonc.github.io — Malware Pers 3 (report)
- blog.cyber5w.com — Analyzing Macro Enabled Office Documents (report)
- Trend Micro — Apt C 36 Updates Its Long Term Spam Campaign Against South Ameri (report)
- blog.morphisec.com — Syk Crypter Discord (report)
- Trend Micro — Blindeagleioclist.Txt (report)
- gi7w0rm.medium.com — Uncovering Ddgroup A Long Time Threat Actor D3B3020625A4 (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Ave Maria (report)