LimeRAT

Malware type
rat, ransomware, cryptominer, ddos, credential-stealer, downloader, keylogger
Family
Malware family
Last IoC activity
2026-07-22 01:55:25
Profile updated
2026-07-07 12:55:16

Context

## Description Simple yet powerful RAT for Windows machines. This project is simple and easy to understand, It should give you a general knowledge about dotNET malwares and how it behaves. --- ## Main Features - **.NET** - Coded in Visual Basic .NET, Client required framework 2.0 or 4.0 dependency, And server is 4.0 - **Connection** - Using pastebin.com as ip:port , Instead of noip.com DNS. And Also using multi-ports - **Plugin** - Using plugin system to decrease stub's size and lower the AV detection - **Encryption** - The communication between server & client is encrypted with AES - **Spreading** - Infecting all files and folders on USB drivers - **Bypass** - Low AV detection and undetected startup method - **Lightweight** - Payload size is about 25 KB - **Anti Virtual Machines** - Uninstall itself if the machine is virtual to avoid scanning or analyzing - **Ransomware** - Encrypting files on all HHD and USB with .Lime extension - **XMR Miner** - High performance Monero CPU miner with user idle\active optimizations - **DDoS** - Creating a powerful DDOS attack to make an online service unavailable - **Crypto Stealer** - Stealing Cryptocurrency sensitive data - **Screen-Locker** - Prevents user from accessing their Windows GUI - **And more** - On Connect Auto Task - Force enable Windows RDP - Persistence - File manager - Passowrds stealer - Remote desktop - Bitcoin grabber - Downloader - Keylogger

Detection coverage

  • 1 YARA rules

Detection rules

  • DITEKSHEN_MALWARE_Win_Limerat (yara-rule)

Reports & references

  • lab52.io — Apt C 36 Recent Activity Analysis (report)
  • blogs.blackberry.com — Dot Net Stubs Sowing The Seeds Of Discord (report)
  • ics-cert.kaspersky.com — Kaspersky Ics Cert Apt Attacks On Industrial Organizations In H1 2021 En (report)
  • blogs.juniper.net — New Pastebin Like Service Used In Multiple Malware Campaigns (report)
  • trellix.com — Targeted Attack On Government Agencies (report)
  • blog.morphisec.com — Tracking Hcrypt An Active Crypter As A Service (report)
  • recordedfuture.com — Tag 144S Persistent Grip On South American Organizations (report)
  • Trend Micro — Apt C 36 Updates Its Long Term Spam Campaign Against South Ameri (report)
  • Cisco Talos — Asyncrat 3Losh Update (report)
  • Trend Micro — Blindeagleioclist.Txt (report)
  • Trend Micro — Water Basilisk Uses New Hcrypt Variant To Flood Victims With Rat Payloads (report)
  • blog.reversinglabs.com — Rats In The Library (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Limerat (report)
  • github.com — Lime Rat (report)
  • lab52.io — Literature Lover Targeting Colombia With Limerat (report)
  • blog.yoroi.company — Limerat Spreads In The Wild (report)
  • any.run — Limerat Malware Analysis (report)
  • felipetarijon.github.io — 2022 12 12 Limerat Infecting Unskilled Threat Actors (report)
  • youtube.com — Watch (report)
  • threatmon.io — Apt Blind Eagles Malware Arsenal Technical Analysis (report)

External references