LimeRAT
- Malware type
- rat, ransomware, cryptominer, ddos, credential-stealer, downloader, keylogger
- Family
- Malware family
- Last IoC activity
- 2026-07-22 01:55:25
- Profile updated
- 2026-07-07 12:55:16
Context
## Description Simple yet powerful RAT for Windows machines. This project is simple and easy to understand, It should give you a general knowledge about dotNET malwares and how it behaves. --- ## Main Features - **.NET** - Coded in Visual Basic .NET, Client required framework 2.0 or 4.0 dependency, And server is 4.0 - **Connection** - Using pastebin.com as ip:port , Instead of noip.com DNS. And Also using multi-ports - **Plugin** - Using plugin system to decrease stub's size and lower the AV detection - **Encryption** - The communication between server & client is encrypted with AES - **Spreading** - Infecting all files and folders on USB drivers - **Bypass** - Low AV detection and undetected startup method - **Lightweight** - Payload size is about 25 KB - **Anti Virtual Machines** - Uninstall itself if the machine is virtual to avoid scanning or analyzing - **Ransomware** - Encrypting files on all HHD and USB with .Lime extension - **XMR Miner** - High performance Monero CPU miner with user idle\active optimizations - **DDoS** - Creating a powerful DDOS attack to make an online service unavailable - **Crypto Stealer** - Stealing Cryptocurrency sensitive data - **Screen-Locker** - Prevents user from accessing their Windows GUI - **And more** - On Connect Auto Task - Force enable Windows RDP - Persistence - File manager - Passowrds stealer - Remote desktop - Bitcoin grabber - Downloader - Keylogger
Detection coverage
- 1 YARA rules
Detection rules
- DITEKSHEN_MALWARE_Win_Limerat (yara-rule)
Reports & references
- lab52.io — Apt C 36 Recent Activity Analysis (report)
- blogs.blackberry.com — Dot Net Stubs Sowing The Seeds Of Discord (report)
- ics-cert.kaspersky.com — Kaspersky Ics Cert Apt Attacks On Industrial Organizations In H1 2021 En (report)
- blogs.juniper.net — New Pastebin Like Service Used In Multiple Malware Campaigns (report)
- trellix.com — Targeted Attack On Government Agencies (report)
- blog.morphisec.com — Tracking Hcrypt An Active Crypter As A Service (report)
- recordedfuture.com — Tag 144S Persistent Grip On South American Organizations (report)
- Trend Micro — Apt C 36 Updates Its Long Term Spam Campaign Against South Ameri (report)
- Cisco Talos — Asyncrat 3Losh Update (report)
- Trend Micro — Blindeagleioclist.Txt (report)
- Trend Micro — Water Basilisk Uses New Hcrypt Variant To Flood Victims With Rat Payloads (report)
- blog.reversinglabs.com — Rats In The Library (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Limerat (report)
- github.com — Lime Rat (report)
- lab52.io — Literature Lover Targeting Colombia With Limerat (report)
- blog.yoroi.company — Limerat Spreads In The Wild (report)
- any.run — Limerat Malware Analysis (report)
- felipetarijon.github.io — 2022 12 12 Limerat Infecting Unskilled Threat Actors (report)
- youtube.com — Watch (report)
- threatmon.io — Apt Blind Eagles Malware Arsenal Technical Analysis (report)