Running RAT

Aliases: running_rat

First seen
2020-05-15 00:00:00
Malware type
rat, keylogger, trojan
Family
Malware family
Last IoC activity
2026-07-18 02:01:00
Profile updated
2026-07-07 15:18:42

Targeted industries: government-and-public-sector technology-and-telecommunications financial-services

Context

NJCCIC characterizes RunningRAT as a remote access trojan (RAT) that operates using two DLL files. When the trojan is loaded onto a system, it executes the first DLL. This is used to disable anti-malware solutions, unpack and execute the main RAT DLL, and gain persistence. The trojan installs a Windows batch file dx.bat that attempts to kill the daumcleaner.exe task, a Korean security program. The file then attempts to remove itself. Once the second DLL is loaded into memory, the first DLL overwrites the IP address for the control server to change the address the trojan communicates with. The second DLL gathers information about the victim's system, including its operating system and driver and processor information. The RAT can log user keystrokes, copy the clipboard, delete files, compress files, clear event logs, shut down the machine, and more. The second DLL also uses several anti-bugging techniques.

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Runningrat (report)
  • hunt.io — Runningrat From Remote Access To Crypto Mining (report)
  • McAfee — Gold Dragon Widens Olympics Malware Attacks Gains Permanent Presence On Victims Systems (report)

External references