StallionRAT

First seen
2021-06-15 00:00:00
Malware type
rat
Profile updated
2026-07-07 13:06:41

Targeted industries: government-and-public-sector technology-and-telecommunications

Context

According to BI.ZONE, StallionRAT allows attackers to execute arbitrary commands, load additional files, and exfiltrate collected data. The malware uses a Telegram bot as their C2 server.

Reports & references

  • bi-zone.medium.com — Cavalry Werewolf Raids Russias Public Sector With Trusted Relationship Attacks E19F7A5C83Ef (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Stallion Rat (report)

External references