I2PRAT

Aliases: I2Parcae

Malware type
rat, credential-stealer
Family
Malware family
Last IoC activity
2026-05-24 01:49:44
Profile updated
2026-07-07 15:06:28

Targeted industries: technology-and-telecommunications media-and-entertainment financial-services

Context

According to Cofense, this malware is notable for having several unique tactics, techniques, and procedures (TTPs), such as Secure Email Gateway (SEG) evasion by proxying emails through legitimate infrastructure, fake CAPTCHAs, abusing hardcoded Windows functionality to hide dropped files, and C2 capabilities over Invisible Internet Project (I2P), a peer-to-peer anonymous network with end-to-end encryption. Upon installation, I2Parcae is capable of disabling Windows Defender, enumerating Windows Security Accounts Manager (SAM) for accounts/groups, stealing browser cookies, and remote access to infected hosts. As of November 2024, I2Parcae appears to be delivered via automated spam messages targeting customer support contact forms on multiple websites. The messages deliver an embedded link purporting to be pornography.

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.I2Prat (report)
  • cofense.com — Custom I2P Rat I2Parcae%E2%80%9D Delivered Via Pornographic Customer Support Form Spam (report)

External references