WarzoneRAT

MITRE ATT&CK: S0670 View on attack.mitre.org

Aliases: Warzone, Ave Maria, AVE_MARIA, AveMariaRAT, Warzone RAT, WarzoneRAT, avemaria

First seen
2018-10-01 00:00:00
Malware type
rat, credential-stealer
Family
Malware family
Operating systems
windows
Related IoCs
1869 (1572 malicious)
Last IoC activity
2026-09-02 02:41:20
Profile updated
2026-07-07 12:38:40

Targeted industries: financial-services government-and-public-sector healthcare-and-pharmaceutical retail-and-hospitality technology-and-telecommunications

Context

WarzoneRAT is a malware-as-a-service remote access tool (RAT) written in C++ that has been publicly available for purchase since at least late 2018.

Recent IoC activity

1,576 malicious indicators in Maltiverse are attributed to WarzoneRAT (S0670). The 20 most recently updated:

TypeIndicatorUpdatedSources
IP address 213.152.187.195 2026-09-03 8
IP address 3.126.224.214 2026-09-03 4
hostname l34d3r.duckdns.org 2026-09-03 1
hostname nan.ydns.eu 2026-09-03 1
hostname dfdgdsasedw.ydns.eu 2026-09-03 1
hostname pubg.ddns.net 2026-09-03 1
hostname huhuhu.ooguy.com 2026-09-03 2
hostname newnex.3utilities.com 2026-09-03 2
hostname goalblistr.ydns.eu 2026-09-03 1
hostname andronmatskiv20.sytes.net 2026-09-03 1
hostname respainc.duckdns.org 2026-09-03 1
hostname msteelwar.ddns.net 2026-09-03 1
hostname yulanda.hopto.org 2026-09-03 1
hostname warzonlogs.duckdns.org 2026-09-03 1
hostname asdfwrkhl.warzonedns.com 2026-09-03 1
hostname urchy.duckdns.org 2026-09-03 1
hostname rex1010.duckdns.org 2026-09-03 2
hostname ccnewcdt.duckdns.org 2026-09-03 2
hostname wz-patient001.duckdns.org 2026-09-03 1
hostname group.loseyourip.com 2026-09-03 1

Detection coverage

  • 2 YARA rules
  • 844 Sigma rules

Malware & tools used

  • Process Discovery (attack-pattern)
  • Keylogging (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • Malicious File (attack-pattern)
  • Disable or Modify Tools (attack-pattern)
  • Exfiltration Over C2 Channel (attack-pattern)
  • Credentials from Web Browsers (attack-pattern)
  • Bypass User Account Control (attack-pattern)
  • Data from Local System (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Proxy (attack-pattern)
  • Symmetric Cryptography (attack-pattern)
  • Remote Desktop Protocol (attack-pattern)
  • Modify Registry (attack-pattern)
  • Component Object Model Hijacking (attack-pattern)
  • Hide Artifacts (attack-pattern)
  • Spearphishing Attachment (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • PowerShell (attack-pattern)
  • Native API (attack-pattern)
  • Video Capture (attack-pattern)
  • Hidden Window (attack-pattern)
  • Process Injection (attack-pattern)
  • Windows Command Shell (attack-pattern)

Used by threat actors

Detection rules

  • DITEKSHEN_MALWARE_Win_Warzonerat (yara-rule)
  • MALPEDIA_Win_Ave_Maria_Auto (yara-rule)

Reports & references

  • pwc.co.uk — Pwc Cyber Threats 2020 A Year In Retrospect (report)
  • Kaspersky — 90703 (report)
  • kaspersky.com — 2019 Fin7 Hacking Group Targets More Than 130 Companies After Leaders Arrest (report)
  • Cisco Talos — Attributing Yorotrooper (report)
  • Kaspersky — 109552 (report)
  • CISA — Aa23 320A (report)
  • uptycs.com — Confucius Apt Deploys Warzone Rat (report)
  • blogs.blackberry.com — Dot Net Stubs Sowing The Seeds Of Discord (report)
  • info.spamhaus.com — 2022%20Q3%20Botnet%20Threat%20Update (report)
  • info.spamhaus.com — 2023%20Q3%20Botnet%20Threat%20Update (report)
  • info.spamhaus.com — 2023%20Q1%20Botnet%20Threat%20Update (report)
  • info.spamhaus.com — 2023%20Q2%20Botnet%20Threat%20Update (report)
  • Cisco Talos — 2020 Year In Malware (report)
  • CISA — Aa23 320A Scattered Spider (report)
  • Kaspersky — 99204 (report)
  • spamhaus.org — 2020 Q2 Spamhaus Botnet Threat Report (report)
  • ciphertechsolutions.com — Roboski Global Recovery Automation (report)
  • securityintelligence.com — Roboski Global Recovery Automation (report)
  • cocomelonc.github.io — Malware Pers 3 (report)
  • blog.cyber5w.com — Analyzing Macro Enabled Office Documents (report)
  • Trend Micro — Apt C 36 Updates Its Long Term Spam Campaign Against South Ameri (report)
  • blog.morphisec.com — Syk Crypter Discord (report)
  • Trend Micro — Blindeagleioclist.Txt (report)
  • gi7w0rm.medium.com — Uncovering Ddgroup A Long Time Threat Actor D3B3020625A4 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Ave Maria (report)

External references