MagicRAT

MITRE ATT&CK: S1182 View on attack.mitre.org

Aliases: MagicRAT

First seen
2022-06-01 00:00:00
Malware type
rat
Family
Malware family
Operating systems
windows
Profile updated
2026-07-07 14:59:05

Targeted industries: energy-and-utilities financial-services government-and-public-sector technology-and-telecommunications

Targeted regions: country_code:kr country_code:us

Context

MagicRAT is a remote access tool developed in C++ and exclusively used by the Lazarus Group threat actor in operations. MagicRAT allows for arbitrary command execution on victim machines and provides basic remote access functionality.

Detection coverage

  • 2 YARA rules
  • 273 Sigma rules

Malware & tools used

  • File Deletion (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • Scheduled Task (attack-pattern)
  • Web Protocols (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Exfiltration Over C2 Channel (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Masquerade File Type (attack-pattern)

Used by threat actors

Detection rules

  • SEKOIA_Implant_Win_Magicrat (yara-rule)
  • SIGNATURE_BASE_MAL_APT_NK_Andariel_Cutiedrop_Magicrat (yara-rule)

Reports & references

  • media.defense.gov — Csa Ransomware Attacks On Ci Fund Dprk Activities (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Magic Rat (report)
  • Cisco Talos — Lazarus Three Rats (report)
  • attackiq.com — Emulating The Highly Sophisticated North Korean Adversary Lazarus Group (report)
  • youtube.com — Watch (report)
  • Cisco Talos — Lazarus Magicrat (report)
  • MITRE ATT&CK — S1182 (report)
  • Cisco Talos — Lazarus Magicrat (report)

External references