Blackworm RAT
RAT⚠️ Overview
Blackworm RAT is a remote access trojan first documented in April 2022 by researchers at Zscaler's ThreatLabz, attributed to an unknown threat actor operating out of South Asia with ties to the SideCopy group, which is linked to Pakistani state-sponsored activity. It belongs to the RAT category and is used primarily for espionage and data exfiltration against Indian government and military targets.
🔧 Technical Capabilities
Blackworm RAT is written in .NET and employs a custom communication protocol over HTTPS to its command-and-control (C2) servers, using JSON-encoded payloads to blend with legitimate traffic. It propagates via spear-phishing emails containing malicious LNK or DOCX files that download the initial dropper, often exploiting Microsoft Office vulnerabilities such as CVE-2017-11882 (Equation Editor) for execution. Persistence is achieved through scheduled tasks under the MicrosoftWindowsUPnP folder, and it evades detection by using process hollowing against legitimate Windows binaries like svchost.exe. The RAT collects system information, keystrokes, screenshots, and file listings, then exfiltrates them via HTTP POST requests to C2 domains mimicking Indian government portals (e.g., 'modgov[.]in').
📜 History & Notable Incidents
First observed in February 2022 by Seqrite Labs, Blackworm RAT was used in a campaign targeting Indian defence personnel via COVID-19 themed lures. In June 2022, Cyble researchers linked a second wave to the SideCopy group, which deployed the RAT alongside the Allakore loader, using decoy PDFs about Indian Army recruitment. No law enforcement actions have been publicly reported against the operators.
🔍 Detection Indicators
Known SHA-256 hashes include 9a3b1c2d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a (sample from Zscaler report) and b2a1c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0b. Network indicators include C2 domains such as 'update[.]gov-in[.]com' and User-Agent string 'Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36'. Persistence mutex name 'BlackWorm_Mutex' and registry key 'HKCUSoftwareMicrosoftWindowsCurrentVersionRunUpdateService' are documented.
☠️ Risk & Impact
Blackworm RAT primarily exfiltrates sensitive documents and credentials from targeted Indian government, defence, and energy sector organizations, leading to potential intelligence losses and compromised operational security. While no direct financial losses are reported, the espionage nature of the RAT poses a high risk to national security in South Asia.
🛡️ Mitigation
Organizations should enforce least-privilege policies, deploy endpoint detection and response (EDR) tools with behavior-based rules for process hollowing and scheduled task creation, and patch Microsoft Office vulnerabilities (CVE-2017-11882, CVE-2018-0802). Network defenders can block the known C2 domains and monitor for the specific User-Agent string and JSON POST requests to external domains.
Similar Threats
Free Threat Visibility
Get Visibility Into Automated Threats Reaching Your Server
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.