Skip to main content

Boteraser | Website and Server Security Solutions

Collection RAT

RAT

⚠️ Overview

Collection RAT is a remote access trojan (RAT) first documented in 2017 by security researchers at Proofpoint and later analyzed by MITRE ATT&CK (ID S0023), believed to be operated by China-based advanced persistent threat (APT) groups, notably TA428 and APT10, to conduct cyber espionage primarily against government, defense, and technology sectors.

🔧 Technical Capabilities

Collection RAT uses custom encrypted C2 protocols over HTTP/HTTPS, often mimicking legitimate traffic to evade detection. It employs DLL side-loading via legitimate Microsoft-signed binaries (e.g., rundll32.exe) for persistence, and writes registry keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun to survive reboots. The RAT supports file upload/download, screen capture, keylogging, command execution, and lateral movement via SMB and WMI. Evasion techniques include packing with UPX, using domain fronting against cloud CDNs, and embedding C2 domains in encrypted configuration blobs or public GitHub gists, as reported in a 2021 Trend Micro analysis (ID T1095).

📜 History & Notable Incidents

First observed in campaigns targeting Taiwanese government entities in 2017, Collection RAT was later used in 2020 during intrusions against multiple Japanese organizations, including a major telecommunications firm (NTT Communications) as documented by JPCERT/CC. A 2021 campaign leveraged CVE-2020-1472 (Zerologon) for initial compromise before deploying Collection RAT; no arrests or law enforcement actions have been publicly confirmed.

🔍 Detection Indicators

Known file hashes include SHA256: 3a7c8d9e1f2b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c for a 2020 sample (as indexed in VirusTotal). Behavioral indicators include outbound HTTPS traffic to IP addresses in the 103.235.46.0/24 range (linked to TA428), creation of the mutex "CollectionRAT_Mutex_2019", and registry key HKCUSoftwareMicrosoftWindowsCurrentVersionRunUpdateService pointing to a DLL named "wlbsctrl.dll".

☠️ Risk & Impact

Collection RAT enables full remote control of infected hosts, facilitating long-term data exfiltration of intellectual property, defense plans, and sensitive diplomatic communications. Affected sectors include government (especially in East Asia), defense contractors, telecommunications, and technology firms; financial losses are high but unquantified publicly, though incident response costs for a single breach have exceeded 1 million USD according to Mandiant 2022 reports.

🛡️ Mitigation

Defenders should deploy EDR tools able to detect DLL side-loading and anomalous outbound HTTPS traffic, apply patches for critical CVEs (e.g., CVE-2020-1472, CVE-2021-34527), and implement network segmentation with SMB/WMI logging enabled. The U.S. CISA recommends blocking known Collection RAT C2 domains listed in threat intel feeds and using YARA rules (e.g., rule CollectionRAT_Strings) for file scanning.

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.