win.innfirat
- First seen
- 2019-09-01 00:00:00
- Malware type
- backdoor, credential-stealer, keylogger, rat, screen-capture
- Family
- Malware family
- Profile updated
- 2026-07-07 15:07:13
Targeted industries: financial-services technology-and-telecommunications
Context
InnifiRAT is coded in .NET and targets personal data on infected devices, with it's top priority appearing to be bitcoin and litecoin wallet data. InffiRAT also includes a backdoor which allows attackers to control the infected host remotely. Possibilities include loggin key stroke, taking pictures with webcam, accessing confidential information, formatting drives, and more. It attempts to steal browser cookies to steal usernames and passwords and monitors the users activities with screenshot functionality.
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Innfirat (report)
- zscaler.com — Innfirat New Rat Aiming Your Cryptocurrency And More (report)