AlmondRAT (Windows)
- First seen
- 2020-06-01 00:00:00
- Malware type
- rat
- Family
- Malware family
- Profile updated
- 2026-07-07 14:43:57
Targeted industries: government-and-public-sector technology-and-telecommunications
Targeted regions: country_code:in country_code:pk country_code:bd
Context
According to Threatray, AlmondRAT is a .NET Remote Access Trojan deployed by the Bitter APT group. It is capable of collecting system information, modifying and exfiltrating data and allows for remote command execution and shares similar functionality with BDarkRAT.
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Almondrat (report)
- secuinfra.com — Whatever Floats Your Boat Bitter Apt Continues To Target Bangladesh (report)
- threatray.com — The Bitter End Unraveling Eight Years Of Espionage Antics Part Two (report)