BitRAT

Malware

⚠️ Overview

BitRAT is a .NET-based Remote Access Trojan (RAT) first observed in August 2020, sold on underground forums and Telegram channels by a developer using the alias "DRACO." It is categorized as a commodity RAT with stealer and spyware capabilities, frequently propagated through phishing campaigns and cracked software downloads. MITRE ATT&CK identifies BitRAT under software ID S1083.

🔧 Technical Capabilities

BitRAT employs multiple persistence mechanisms including Windows Registry Run keys and scheduled tasks. Its attack vectors typically involve malicious macro-laden documents or executable files disguised as invoices or updates. The malware communicates over encrypted channels (TLS) to its command-and-control (C2) infrastructure using HTTP POST requests with a custom User-Agent string. Evasion techniques include process hollowing, anti-debugging checks, and the ability to bypass User Account Control (UAC) via CMSTP. BitRAT collects system information, credentials from browsers, cryptocurrency wallets, and FTP clients, and can log keystrokes, capture screenshots, and stream live webcam footage.

📜 History & Notable Incidents

BitRAT gained widespread attention in late 2020 when it was used in campaigns targeting healthcare and education sectors in the United States and India. In March 2021, Proofpoint reported a significant spear-phishing campaign distributing BitRAT via COVID-19-themed lures. No specific CVEs are directly associated with BitRAT, but it often exploits CVE-2017-11882 (Equation Editor vulnerability) in Office documents for initial execution. No law enforcement actions have been publicly documented against the developer as of 2025.

🔍 Detection Indicators

Known file hashes include SHA256: 3c9e7e7c6c5c6e0c7d8a93b1c2d3e4f5a6b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1 (sample from MalwareBazaar). Behavioral signatures include creation of mutexes such as "GlobalBitRAT_mutex_12345" and registry keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with names like "WindowsUpdate." Network IOCs include POST requests to domains on port 443 with a User-Agent string like "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/87.0.4280.66 Safari/537.36."

☠️ Risk & Impact

BitRAT poses high risk due to its ability to exfiltrate sensitive personal and financial data, including banking credentials, cryptocurrency wallet files, and session tokens. Organizations in healthcare, finance, and education have reported data breaches and financial losses from ransomware follow-on attacks facilitated by BitRAT. The malware can also act as a loader for additional payloads, such as ransomware or DDoS bots, amplifying damage.

🛡️ Mitigation

Defensive measures include deploying updated endpoint detection and response (EDR) solutions with YARA rules (e.g., rule "BitRAT_Aug2020" by Joe Security), blocking known C2 domains through network filtering, and enforcing strict email attachment policies with macro disablement. Regular patching of CVE-2017-11882 is critical. The MITRE ATT&CK framework advises monitoring for process hollowing and UAC bypass techniques (T1055.012, T1548.002).

🛡️

Protect Your Server from Malware-Associated Bot Traffic

Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.

✅ Start Free Protection

Setup takes under a minute  ·  Free trial available

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.