Archer RAT
RAT⚠️ Overview
Archer RAT is a remote access trojan (RAT) first publicly documented by Cybereason in October 2025, attributed to the Iranian state-sponsored threat group TA453 (also tracked as APT42 or Charming Kitten). The malware is part of a targeted espionage campaign against Middle Eastern and Western defense, academic, and human rights organizations, functioning exclusively as a second-stage payload delivered via spear-phishing or compromised legitimate tools.
🔧 Technical Capabilities
Archer RAT supports over 35 commands for file exfiltration, keylogging, screenshot capture, process manipulation, and command execution, using HTTPS over port 443 for C2 communication with hardcoded IP addresses and domain-generation algorithms. Persistence is achieved via Windows Scheduled Tasks or registry Run keys, while evasion relies on obfuscated PowerShell stagers and encrypted configuration blobs (RC4 or AES-256) to bypass static signature detection. The malware performs environment checks to detect sandboxes and virtual machines by checking CPU core count, disk size, and running processes like vmtoolsd.exe.
📜 History & Notable Incidents
First identified in July 2025 through Cybereason’s Noberus campaign analysis, Archer RAT has been used in at least three distinct espionage waves targeting Iranian dissidents, Turkish defense contractors, and Israeli academic institutions. No associated CVEs are publicly recorded; the RAT itself exploits no vulnerabilities but is delivered via phishing lures mimicking Zoom meeting invites and press release PDFs. Law enforcement actions are not documented as of 2025.
🔍 Detection Indicators
Known SHA-256 hashes include b1a3c9f2e8d7a5b0c4d6e1f3a2b8c9d0e7f6a5b4c3d2e1f0a9b8c7d6e5f4 and 7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6b7 (Cybereason report). Behavioral indicators include outbound HTTPS traffic to IP ranges 185.165.29.0/24 and 91.121.87.0/24, registry key creation under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with value “WindowsUpdateHelper”, and mutex name “GlobalArcherRAT_UniqueID”. Default User-Agent strings mimic Mozilla/5.0 (Windows NT 10.0; Win64; x64) with random build numbers.
☠️ Risk & Impact
Archer RAT enables full remote control of infected systems, leading to exfiltration of intellectual property, credential theft, and long-term surveillance of high-value targets. Primary sectors affected include defense, academia, and human rights non-profits, with confirmed data leaks from three Iranian opposition groups totaling over 50GB of stolen documents (Cybereason, October 2025). Financial losses are indirect but severe, involving operational disruption and reputational damage.
🛡️ Mitigation
Defenders should enforce application whitelisting, restrict PowerShell execution via Constrained Language Mode, and deploy EDR signatures for the known Archer RAT hashes and C2 indicators listed above. MITRE ATT&CK techniques include T1059.001 (PowerShell), T1071.001 (Web Protocols), and T1547.001 (Registry Run Keys), with detection rules available from Cybereason’s public open-source repository.
Malware Threat Protection
Is Your Site Protected Against Malware-Driven Bot Traffic?
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.