NineRAT
- Malware type
- rat
- Family
- Malware family
- Profile updated
- 2026-07-07 14:50:20
Targeted industries: education-and-nonprofits technology-and-telecommunications
Context
NineRAT is a remote access Trojan that allows attackers to gain unauthorized access and control of infected systems. It is typically used in cyber espionage campaigns, targeting industries like education and technology for data exfiltration and observation.
Detection coverage
- 4 YARA rules
Detection rules
- SEKOIA_Loader_Win_Ninerat (yara-rule)
- SEKOIA_Dropper_Win_Ninerat (yara-rule)
- SEKOIA_Rat_Win_Ninerat (yara-rule)
- MALPEDIA_Win_Ninerat_Auto (yara-rule)
Reports & references
- Cisco Talos — Lazarus New Rats Dlang And Telegram (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Ninerat (report)