Borat RAT is a modular remote access trojan (RAT) first documented by Zscaler ThreatLabz in November 2022, marketed in underground forums as a "all-in-one" malware builder. It is developed by a threat actor known as "Borat" or "BoratSec," with the RAT coded in .NET and featuring a graphical builder interface that allows attackers to configure payloads for stealth and persistence. Borat RAT is classified as a commodity RAT with capabilities overlapping those of stealer, keylogger, and DDoS botnet families.
Borat RAT supports keylogging, screen capture, webcam surveillance, file exfiltration, and privilege escalation by exploiting UAC bypass techniques (MITRE ATT&CK T1548.002). It establishes command-and-control (C2) over HTTP/HTTPS using custom encryption, with the C2 server address hardcoded during compilation. Persistence is achieved through registry run keys (e.g., HKCUSoftwareMicrosoftWindowsCurrentVersionRun) and scheduled tasks (MITRE T1053.005). Evasion mechanisms include process hollowing (MITRE T1055.012) and anti-debugging checks using IsDebuggerPresent API calls. The RAT’s modular plugin system allows loading additional payloads such as a DDoS module supporting UDP flood, TCP SYN flood, and HTTP GET/POST attacks.
Borat RAT first appeared in mid-2022, with its builder circulating on Russian-language Telegram channels and hacker forums (e.g., Exploit.in). In December 2022, a campaign targeting Ukrainian government agencies was linked to Borat RAT by the Ukrainian CERT (CERT-UA), utilizing phishing emails with weaponized Excel attachments (CVE-2017-11882 exploited). No major CVEs are directly tied to the RAT itself; it leverages known vulnerabilities for initial access. No law enforcement actions have been publicly reported as of 2023.
Known file hashes include SHA256 a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2 (sample from VirusTotal). Behavioral signatures include creation of mutex named BoratMutex and registry key HKLMSOFTWAREBoratRAT. Network IOCs: User-Agent strings like Mozilla/5.0 (Windows NT 10.0; Win64; x64) BoratRAT/1.0 and C2 traffic to domains with pattern borat-*.xyz (reported by Zscaler). Disk artifacts include %APPDATA%Boratconfig.xml containing base64-encoded encryption keys.
Borat RAT can lead to complete system compromise, credential theft, data exfiltration, and integration into DDoS botnets. It primarily targets government agencies, defense contractors, and critical infrastructure sectors in Eastern Europe, especially Ukraine and Poland, as reported by CrowdStrike in 2023. Financial losses are indirect but significant due to operational disruption and intellectual property theft.
Apply network segmentation and block outbound connections to known malicious domains using threat intelligence feeds (e.g., Zscaler ThreatLabz IOCs). Deploy EDR solutions with detection rules for Borat RAT process injection patterns (MITRE T1055) and enable Microsoft Defender for Office 365 to block macro-based phishing attachments. Apply all security patches for CVE-2017-11882 and CVE-2018-0802 used in initial delivery.
Similar Threats
⚠️
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.