win.innfirat

First seen
2019-09-01 00:00:00
Malware type
backdoor, credential-stealer, keylogger, rat, screen-capture
Family
Malware family
Profile updated
2026-07-07 15:07:13

Targeted industries: financial-services technology-and-telecommunications

Context

InnifiRAT is coded in .NET and targets personal data on infected devices, with it's top priority appearing to be bitcoin and litecoin wallet data. InffiRAT also includes a backdoor which allows attackers to control the infected host remotely. Possibilities include loggin key stroke, taking pictures with webcam, accessing confidential information, formatting drives, and more. It attempts to steal browser cookies to steal usernames and passwords and monitors the users activities with screenshot functionality.

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Innfirat (report)
  • zscaler.com — Innfirat New Rat Aiming Your Cryptocurrency And More (report)

External references