BitRAT

First seen
2021-08-01 00:00:00
Malware type
rat, credential-stealer, cryptominer, ddos, keylogger
Family
Malware family
Last IoC activity
2026-07-22 01:55:25
Profile updated
2026-07-07 13:46:38

Targeted industries: technology-and-telecommunications financial-services government-and-public-sector retail-and-hospitality

Context

According to Bitdefender, BitRAT is a notorious remote access trojan (RAT) marketed on underground cybercriminal web markets and forums. Its price tag of $20 for lifetime access makes it irresistible to cybercriminals and helps the malicious payload spread. Furthermore, each buyer’s modus operandi makes BitRAT even harder to stop, considering it can be employed in various operations, such as trojanized software, phishing and watering hole attacks. BitRAT’s popularity arises from its versatility. The malicious tool can perform a wide range of operations, including data exfiltration, UAC bypass, DDoS attacks, clipboard monitoring, gaining unauthorized webcam access, credential theft, audio recording, XMRig coin mining and generic keylogging.

Reports & references

  • blog.morphisec.com — The Babadeda Crypter Targeting Crypto Nft Defi Communities (report)
  • blogs.blackberry.com — Dot Net Stubs Sowing The Seeds Of Discord (report)
  • Trend Micro — Ssl Tls Technical Brief (report)
  • cocomelonc.github.io — Malware Tricks 44 (report)
  • ciphertechsolutions.com — Roboski Global Recovery Automation (report)
  • securityintelligence.com — Roboski Global Recovery Automation (report)
  • threatresearch.ext.hp.com — Hp Bromium Threat Insights Report Q4 2020 (report)
  • blog.morphisec.com — Journey%20Of%20A%20Crypto%20Scammer%20 %20Nft 001%20%7C%20Morphisec%20%7C%20Threat%20Report (report)
  • recordedfuture.com — Tag 144S Persistent Grip On South American Organizations (report)
  • Trend Micro — Apt C 36 Updates Its Long Term Spam Campaign Against South Ameri (report)
  • Trend Micro — Blindeagleioclist.Txt (report)
  • gi7w0rm.medium.com — Uncovering Ddgroup A Long Time Threat Actor D3B3020625A4 (report)
  • community.riskiq.com — Ade260C6 (report)
  • fortinet.com — Phishing Campaign Delivering Fileless Malware (report)
  • Trend Micro — Water Basilisk Uses New Hcrypt Variant To Flood Victims With Rat Payloads (report)
  • blog.checkpoint.com — A German Car Attack On German Vehicle Businesses (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Bit Rat (report)
  • forensicitguy.github.io — Hcrypt Injecting Bitrat Analysis (report)
  • krabsonsecurity.com — Bitrat The Latest In Copy Pasted Malware By Incompetent Developers (report)
  • github.com — Readme.Md (report)
  • asec.ahnlab.com — 32781 (report)
  • fortinet.com — Nft Lure Used To Distribute Bitrat (report)
  • bitdefender.com — Bitrat Malware Seen Spreading Through Unofficial Microsoft Windows Activators (report)
  • krabsonsecurity.com — Bitrat Pt 2 Hidden Browser Socks5 Proxy And Unknownproducts Unmasked (report)
  • research.checkpoint.com — Apomacrosploit Apocalyptical Fud Race (report)

External references