NineRAT

Malware type
rat
Family
Malware family
Profile updated
2026-07-07 14:50:20

Targeted industries: education-and-nonprofits technology-and-telecommunications

Context

NineRAT is a remote access Trojan that allows attackers to gain unauthorized access and control of infected systems. It is typically used in cyber espionage campaigns, targeting industries like education and technology for data exfiltration and observation.

Detection coverage

  • 4 YARA rules

Detection rules

  • SEKOIA_Loader_Win_Ninerat (yara-rule)
  • SEKOIA_Dropper_Win_Ninerat (yara-rule)
  • SEKOIA_Rat_Win_Ninerat (yara-rule)
  • MALPEDIA_Win_Ninerat_Auto (yara-rule)

Reports & references

  • Cisco Talos — Lazarus New Rats Dlang And Telegram (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Ninerat (report)

External references