STRRAT
- First seen
- 2020-06-01 00:00:00
- Malware type
- rat, credential-stealer, keylogger
- Family
- Malware family
- Last IoC activity
- 2026-07-22 04:08:12
- Profile updated
- 2026-07-07 12:45:40
Targeted industries: financial-services technology-and-telecommunications
Context
STRRAT is a Java-based RAT, which makes extensive use of plugins to provide full remote access to an attacker, as well as credential stealing, key logging and additional plugins. The RAT has a focus on stealing credentials of browsers and email clients, and passwords via keylogging. It supports the following browsers and email clients: Firefox, Internet Explorer, Chrome, Foxmail, Outlook, Thunderbird. Since Version 1.2 and above, STRRAT was infamous for its ransomware-like behavior of appending the file name extension .crimson to files. Version 1.5 is notably more obfuscated and modular than previous versions, but the backdoor functions mostly remain the same: collect browser passwords, run remote commands and PowerShell, log keystrokes, among others. Version 1.5 of STRRAT Malware includes a proper encryption routine, though currently pretty simple to revert.
Reports & references
- deepinstinct.com — Understanding The Windows Javascript Threat Landscape (report)
- threatresearch.ext.hp.com — Javascript Malware Dispensing Rats Into The Wild (report)
- malpedia.caad.fkie.fraunhofer.de — Jar.Strrat (report)
- fortinet.com — New Strrat Rat Phishing Campaign (report)
- github.com — Microsoft 365 Defender Hunting Queries (report)
- securityscorecard.com — How To Analyze Java Malware %E2%80%93 A Case Study Of Strrat (report)
- forensicitguy.github.io — Strrat Attached To Msi (report)
- jaiminton.com — Strrat (report)
- resources.securityscorecard.com — Analyze Java Malware Strrat (report)
- umbrella.cisco.com — Cybersecurity Threat Spotlight Strrat Zloader Honeygain (report)
- gdatasoftware.com — Strrat Crimson (report)
- any.run — Strrat Malware Analysis Of A Jar Archive (report)
- threatresearch.ext.hp.com — Hp Wolf Security Threat Insights Report Q3 2021 (report)
- isc.sans.edu — 27798 (report)
- fortinet.com — Vcurms A Simple And Functional Weapon (report)
- twitter.com — 1395138347601854465 (report)