Kiler RAT

Aliases: Njw0rm

First seen
2013-05-01 00:00:00
Malware type
rat, credential-stealer, worm
Family
Malware family
Last IoC activity
2026-07-20 00:38:49
Profile updated
2026-07-07 15:39:24

Targeted industries: government-and-public-sector technology-and-telecommunications

Context

This remote access trojan (RAT) has capabilities ranging from manipulating the registry to opening a reverse shell. From stealing credentials stored in browsers to accessing the victims webcam. Through the Command & Control (CnC) server software, the attacker has capabilities to create and configure the malware to spread utilizing physic devices, such as USB drives, but also to use the victim as a pivot point to gain more access laterally throughout the network. This remote access trojan could be classified as a variant of the well known njrat, as they share many similar features such as their display style, several abilities and a general template for communication methods . However, where njrat left off KilerRat has taken over. KilerRat is a very feature rich RAT with an active development force that is rapidly gaining in popularity amongst the middle eastern community and the world.

Related threat objects

Reports & references

  • alienvault.com — Kilerrat Taking Over Where Njrat Remote Access Trojan Left Off (report)

External references