WmRAT
- Malware type
- rat, screen-capture
- Family
- Malware family
- Profile updated
- 2026-07-07 13:00:35
Context
According to Proofpoint, WmRAT is a remote access trojan (RAT) written in C++ that uses sockets for communications and has standard RAT functionality. The RAT can gather basic host information, upload or download files, take screenshots, get geolocation data of the target machine, enumerate directories and files, and run arbitrary commands via cmd or PowerShell. The malware also generates a number of junk threads, potentially to mislead researchers or responders investigating the samples.
Detection coverage
- 1 YARA rules
Detection rules
- SIGNATURE_BASE_APT_IN_TA397_Wmrat (yara-rule)
Reports & references
- proofpoint.com — Hidden Plain Sight Ta397S New Attack Chain Delivers Espionage Rats (report)
- threatray.com — The Bitter End Unraveling Eight Years Of Espionage Antics Part Two (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Wm Rat (report)
- blog.eclecticiq.com — Pakistan Telecommunication Company Ptcl Targeted By Bitter Apt During Heightened Regional Conflict (report)