Running RAT
Aliases: running_rat
- First seen
- 2020-05-15 00:00:00
- Malware type
- rat, keylogger, trojan
- Family
- Malware family
- Last IoC activity
- 2026-07-18 02:01:00
- Profile updated
- 2026-07-07 15:18:42
Targeted industries: government-and-public-sector technology-and-telecommunications financial-services
Context
NJCCIC characterizes RunningRAT as a remote access trojan (RAT) that operates using two DLL files. When the trojan is loaded onto a system, it executes the first DLL. This is used to disable anti-malware solutions, unpack and execute the main RAT DLL, and gain persistence. The trojan installs a Windows batch file dx.bat that attempts to kill the daumcleaner.exe task, a Korean security program. The file then attempts to remove itself. Once the second DLL is loaded into memory, the first DLL overwrites the IP address for the control server to change the address the trojan communicates with. The second DLL gathers information about the victim's system, including its operating system and driver and processor information. The RAT can log user keystrokes, copy the clipboard, delete files, compress files, clear event logs, shut down the machine, and more. The second DLL also uses several anti-bugging techniques.
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Runningrat (report)
- hunt.io — Runningrat From Remote Access To Crypto Mining (report)
- McAfee — Gold Dragon Widens Olympics Malware Attacks Gains Permanent Presence On Victims Systems (report)